From patchwork Wed Aug 26 08:12:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96421 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 525B3C61DC4 for ; Wed, 26 Aug 2026 08:13:26 +0000 (UTC) Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7691.1787732003200354880 for ; Wed, 26 Aug 2026 01:13:23 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=RB6Y85Ia; spf=pass (domain: cisco.com, ip: 173.37.142.94, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=14759; q=dns/txt; s=iport01; t=1787732003; x=1788941603; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=TERPuGqb5o5XoOzdGapMmaScUZRzjyMxbvwVKFeR+uE=; b=RB6Y85IaGgWgBH0Dm2Rsxqo3PX+mnUI9SMWHdsC/V6pdHjM+ZIf94uO3 P4zlDrrPXMQFfceaZuAAAgdb1qDhJlDknJGw2dreAUiFXbJ7NHLfTp+wv 2a/g3lNG4oaAX7rMdWTRbekgRMhSa7bKGmhCP1YL2ePjQlOKExP5UdhgF I2mT90WmRBBDIRF0YDyV6hSgjqlWLvqgfTl7+ueuln16BoPPzFef0hx9d 5rJD5KVac0iFoJ7l4lU33pREtsfCUNr1RAKSIHLcw2wRWU1z9XDvuNoR1 WZjJjIkiX12JZPyD8CNKgfVpaWXsH8q7Kc2x4eDG56NPMcU1eLeFs+JHo g==; X-CSE-ConnectionGUID: qcVk2MB/RM+OS69090tqzA== X-CSE-MsgGUID: FyutvAVxSie/ZTOY9LGeOg== X-IPAS-Result: A0AIAAC6n45q/48QJK1aGwEBAQEBAQEBBQEBARIBAQEDAwEBAYF8BgEBAQsBglZ0X0JJBIxuiVgDnhuBfg8BAQEPRA0EAQGFBQKNbAImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDYZaAQIBAzIBRhAcAQIBAi8rHQYIGYMDgnQCARG/BoIsgQGDaAJDUNswAQsUAQWBMwGFPogiXRgBgkmCMycbG4FygRUygzeBBYFcAQGIJQSCIoEMgVqBFpBySIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQQIxk2fIEJXoErKWABEheBCYIHAoJaggUCAUlDDgdHPgsYDUgRLDcUGQQ+bgeOax+BekgHASwQJBoTASsFgQBIHxcBKAU1kmsJhD2LaoIhgTWfWgoog3aMIpVUM4QElBeSUQuYfYJZizGWDkKEaYFoPIFHCwdwFTuCZwkKQBkPjioCAQsLg2CBf4MUxyYkNQIBCDIBAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:B8vBEK1THA1zA4A2mfbD5YRwkn2cJEfYwER7XKvMYLTBsI5bp2FTn zBKDDjTbqqOYmCmf9hzb47k9EwCv8WGyNQxQFNr3Hw8FHgiRegpqji6wuYcGwvIc6UvmWo+t 512huHodZ5yFjmH4E/xbtANlFEkvYmQXL3wFeXYDS54QA5gWU8JhAlq8wIDqtYAbeORXUXX5 Lsen+WFYAX7g24ubDpNg06+gEoHUMra6WtwUmMWPZinjHeG/1EJAZQWI72GLneQauF8Au6gS u/f+6qy92Xf8g1FIovNfmHTKxBirhb6ZGBiu1IOM0SQqkEqSh8ajs7XAMEhhXJ/0F1lqTzeJ OJl7vRcQS9xVkHFdX90vxNwS0mSNoUekFPLzOTWXcG7lyX7n3XQL/pGFUoIPtc90KFNJCJpz qJJcGFVcgmRrrfjqF67YrEEasULJc3vOsYb/3pn1zycVahgSpHYSKKM7thdtNsyrpkRRrCFO YxAN3w2ME+ojx5nYj/7DLo+gOehhXDlWzZZs1mS46Ew5gA/ySQhiem2aYWKIYbiqcN9sFeFu nzvwXTCAxxdBuC4+Guh3X+Libqa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYVX95WVul/4waXx++MvUCSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXMIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:1nt/0KkDjSCwe4sS6Iy6Jbzl1CnpDfL03DAbv31ZSRFFG/FwWf rAoB19726StN9/YhAdcLy7VZVoBEmsl6KdgrNhWYtKIjOHhILAFugLhuHfKn/bakjDH4Vmu5 uIHZITNDTYNykdsS+D2njaL/8QhP+a7auvmeDSi11pTQ1sduVcyj0RMHfjLqWzLzM2fqbQ0/ Gnl7J6mwY= X-Talos-CUID: 9a23:EiYogmsQ+B7sWViFBwvnlt5t6Is8eUPellL6ZHWdSkFSFuzNGAeM4bFNxp8= X-Talos-MUID: 9a23:hFg2pg1lBUK2isWr9FVUeCG9eTUjzbWzFF4kr4U9usTDBxBXCma5ozmQTdpy X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="819317732" Received: from alln-l-core-06.cisco.com ([173.36.16.143]) by alln-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:22 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-06.cisco.com (Postfix) with ESMTPS id ECC4A18000247; Wed, 26 Aug 2026 08:13:21 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 92B0CCE1BBC; Wed, 26 Aug 2026 01:13:21 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 01/11] u-boot, u-boot-tools: Fix CVE-2026-46728 Date: Wed, 26 Aug 2026 01:12:50 -0700 Message-Id: <7ca025aefed43b95e6f5a8fa13db65781b6f6eb1.1787731424.git.hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-06.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244328 From: Hetvi Thakar This patch applies the upstream U-Boot fix referenced by the advisory in [2], using the commit shown in [1]. The fix rebuilds the FIT signed-node list from the selected configuration instead of trusting the attacker-controlled hashed-nodes property. [1] https://github.com/u-boot/u-boot/commit/2092322b31cc [2] https://nvd.nist.gov/vuln/detail/CVE-2026-46728 Signed-off-by: Hetvi Thakar --- .../u-boot/files/CVE-2026-46728.patch | 379 ++++++++++++++++++ .../u-boot/u-boot-tools_2024.01.bb | 2 + meta/recipes-bsp/u-boot/u-boot_2024.01.bb | 1 + 3 files changed, 382 insertions(+) create mode 100644 meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch diff --git a/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch new file mode 100644 index 0000000000..e6737f38a6 --- /dev/null +++ b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch @@ -0,0 +1,379 @@ +From 2092322b31cc8b1f8c9e2e238d1043ae0637b241 Mon Sep 17 00:00:00 2001 +From: Simon Glass +Date: Thu, 5 Mar 2026 18:20:09 -0700 +Subject: [PATCH] boot: Add fit_config_get_hash_list() to build signed node + list + +The hashed-nodes property in a FIT signature node lists which FDT paths +are included in the signature hash. It is intended as a hint so should +not be used for verification. + +Add a function to build the node list from scratch by iterating the +configuration's image references. Skip properties known not to be image +references. For each image, collect the path plus all hash and cipher +subnodes. + +Use the new function in fit_config_check_sig() instead of reading +'hashed-nodes'. + +Update the test_vboot kernel@ test case: fit_check_sign now catches the +attack at signature-verification time (the @-suffixed node is hashed +instead of the real one, causing a mismatch) rather than at +fit_check_format() time. + +Update the docs to cover this. The FIT spec can be updated separately. + +Signed-off-by: Simon Glass +Closes: https://lore.kernel.org/u-boot/20260302220937.3682128-1-trini@konsulko.com/ +Reported-by: Apple Security Engineering and Architecture (SEAR) +Tested-by: Tom Rini + +CVE: CVE-2026-46728 +Upstream-Status: Backport [https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241] + +Backport Changes: +- Use the v2024.01 FIT_COMP_PROP name for the compatible property. +- Adapt test_vboot.py context to the v2024.01 test layout. + +(cherry picked from commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241) +Signed-off-by: Hetvi Thakar +--- + boot/image-fit-sig.c | 227 +++++++++++++++++++++++++++++------- + doc/usage/fit/signature.rst | 19 ++- + test/py/tests/test_vboot.py | 8 +- + 3 files changed, 201 insertions(+), 53 deletions(-) + +diff --git a/boot/image-fit-sig.c b/boot/image-fit-sig.c +index 12369896..79e7ff93 100644 +--- a/boot/image-fit-sig.c ++++ b/boot/image-fit-sig.c +@@ -19,6 +19,7 @@ DECLARE_GLOBAL_DATA_PTR; + #include + + #define IMAGE_MAX_HASHED_NODES 100 ++#define FIT_MAX_HASH_PATH_BUF 4096 + + /** + * fit_region_make_list() - Make a list of image regions +@@ -225,6 +226,179 @@ int fit_image_verify_required_sigs(const void *fit, int image_noffset, + return 0; + } + ++/** ++ * fit_config_add_hash() - Add hash nodes for one image to the node list ++ * ++ * Adds the image path, all its hash-* subnode paths, and its cipher ++ * subnode path (if present) to the packed buffer. ++ * ++ * @fit: FIT blob ++ * @image_noffset: Image node offset (e.g. /images/kernel-1) ++ * @node_inc: Array of path pointers to fill ++ * @count: Pointer to current count (updated on return) ++ * @max_nodes: Maximum entries in @node_inc ++ * @buf: Buffer for packed path strings ++ * @buf_used: Pointer to bytes used in @buf (updated on return) ++ * @buf_len: Total size of @buf ++ * Return: 0 on success, -ve on error ++ */ ++static int fit_config_add_hash(const void *fit, int image_noffset, ++ char **node_inc, int *count, int max_nodes, ++ char *buf, int *buf_used, int buf_len) ++{ ++ int noffset, hash_count, ret, len; ++ ++ if (*count >= max_nodes) ++ return -ENOSPC; ++ ++ ret = fdt_get_path(fit, image_noffset, buf + *buf_used, ++ buf_len - *buf_used); ++ if (ret < 0) ++ return -ENOENT; ++ len = strlen(buf + *buf_used) + 1; ++ node_inc[(*count)++] = buf + *buf_used; ++ *buf_used += len; ++ ++ /* Add all this image's hash subnodes */ ++ hash_count = 0; ++ for (noffset = fdt_first_subnode(fit, image_noffset); ++ noffset >= 0; ++ noffset = fdt_next_subnode(fit, noffset)) { ++ const char *name = fit_get_name(fit, noffset, NULL); ++ ++ if (strncmp(name, FIT_HASH_NODENAME, ++ strlen(FIT_HASH_NODENAME))) ++ continue; ++ if (*count >= max_nodes) ++ return -ENOSPC; ++ ret = fdt_get_path(fit, noffset, buf + *buf_used, ++ buf_len - *buf_used); ++ if (ret < 0) ++ return -ENOENT; ++ len = strlen(buf + *buf_used) + 1; ++ node_inc[(*count)++] = buf + *buf_used; ++ *buf_used += len; ++ hash_count++; ++ } ++ ++ if (!hash_count) { ++ printf("No hash nodes in image '%s'\n", ++ fdt_get_name(fit, image_noffset, NULL)); ++ return -ENOMSG; ++ } ++ ++ /* Add this image's cipher node if present */ ++ noffset = fdt_subnode_offset(fit, image_noffset, FIT_CIPHER_NODENAME); ++ if (noffset != -FDT_ERR_NOTFOUND) { ++ if (noffset < 0) ++ return -EIO; ++ if (*count >= max_nodes) ++ return -ENOSPC; ++ ret = fdt_get_path(fit, noffset, buf + *buf_used, ++ buf_len - *buf_used); ++ if (ret < 0) ++ return -ENOENT; ++ len = strlen(buf + *buf_used) + 1; ++ node_inc[(*count)++] = buf + *buf_used; ++ *buf_used += len; ++ } ++ ++ return 0; ++} ++ ++/** ++ * fit_config_get_hash_list() - Build the list of nodes to hash ++ * ++ * Works through every image referenced by the configuration and collects the ++ * node paths: root + config + all referenced images with their hash and ++ * cipher subnodes. ++ * ++ * Properties known not to be image references (description, compatible, ++ * default, load-only) are skipped, so any new image type is covered by default. ++ * ++ * @fit: FIT blob ++ * @conf_noffset: Configuration node offset ++ * @node_inc: Array to fill with path string pointers ++ * @max_nodes: Size of @node_inc array ++ * @buf: Buffer for packed null-terminated path strings ++ * @buf_len: Size of @buf ++ * Return: number of entries in @node_inc, or -ve on error ++ */ ++static int fit_config_get_hash_list(const void *fit, int conf_noffset, ++ char **node_inc, int max_nodes, ++ char *buf, int buf_len) ++{ ++ const char *conf_name; ++ int image_count; ++ int prop_offset; ++ int used = 0; ++ int count = 0; ++ int ret, len; ++ ++ conf_name = fit_get_name(fit, conf_noffset, NULL); ++ ++ /* Always include the root node and the configuration node */ ++ if (max_nodes < 2) ++ return -ENOSPC; ++ ++ len = 2; /* "/" + nul */ ++ if (len > buf_len) ++ return -ENOSPC; ++ strcpy(buf, "/"); ++ node_inc[count++] = buf; ++ used += len; ++ ++ len = snprintf(buf + used, buf_len - used, "%s/%s", FIT_CONFS_PATH, ++ conf_name) + 1; ++ if (used + len > buf_len) ++ return -ENOSPC; ++ node_inc[count++] = buf + used; ++ used += len; ++ ++ /* Process each image referenced by the config */ ++ image_count = 0; ++ fdt_for_each_property_offset(prop_offset, fit, conf_noffset) { ++ const char *prop_name; ++ int img_count, i; ++ ++ fdt_getprop_by_offset(fit, prop_offset, &prop_name, NULL); ++ if (!prop_name) ++ continue; ++ ++ /* Skip properties that are not image references */ ++ if (!strcmp(prop_name, FIT_DESC_PROP) || ++ !strcmp(prop_name, FIT_COMP_PROP) || ++ !strcmp(prop_name, FIT_DEFAULT_PROP)) ++ continue; ++ ++ img_count = fdt_stringlist_count(fit, conf_noffset, prop_name); ++ for (i = 0; i < img_count; i++) { ++ int noffset; ++ ++ noffset = fit_conf_get_prop_node_index(fit, ++ conf_noffset, ++ prop_name, i); ++ if (noffset < 0) ++ continue; ++ ++ ret = fit_config_add_hash(fit, noffset, node_inc, ++ &count, max_nodes, buf, &used, ++ buf_len); ++ if (ret < 0) ++ return ret; ++ ++ image_count++; ++ } ++ } ++ ++ if (!image_count) { ++ printf("No images in config '%s'\n", conf_name); ++ return -ENOMSG; ++ } ++ ++ return count; ++} ++ + /** + * fit_config_check_sig() - Check the signature of a config + * +@@ -265,20 +439,16 @@ static int fit_config_check_sig(const void *fit, int noffset, int conf_noffset, + FIT_DATA_POSITION_PROP, + FIT_DATA_OFFSET_PROP, + }; +- +- const char *prop, *end, *name; ++ char *node_inc[IMAGE_MAX_HASHED_NODES]; ++ char hash_buf[FIT_MAX_HASH_PATH_BUF]; + struct image_sign_info info; + const uint32_t *strings; +- const char *config_name; + uint8_t *fit_value; + int fit_value_len; +- bool found_config; + int max_regions; +- int i, prop_len; + char path[200]; + int count; + +- config_name = fit_get_name(fit, conf_noffset, NULL); + debug("%s: fdt=%p, conf='%s', sig='%s'\n", __func__, key_blob, + fit_get_name(fit, noffset, NULL), + fit_get_name(key_blob, required_keynode, NULL)); +@@ -293,45 +463,12 @@ static int fit_config_check_sig(const void *fit, int noffset, int conf_noffset, + return -1; + } + +- /* Count the number of strings in the property */ +- prop = fdt_getprop(fit, noffset, "hashed-nodes", &prop_len); +- end = prop ? prop + prop_len : prop; +- for (name = prop, count = 0; name < end; name++) +- if (!*name) +- count++; +- if (!count) { +- *err_msgp = "Can't get hashed-nodes property"; +- return -1; +- } +- +- if (prop && prop_len > 0 && prop[prop_len - 1] != '\0') { +- *err_msgp = "hashed-nodes property must be null-terminated"; +- return -1; +- } +- +- /* Add a sanity check here since we are using the stack */ +- if (count > IMAGE_MAX_HASHED_NODES) { +- *err_msgp = "Number of hashed nodes exceeds maximum"; +- return -1; +- } +- +- /* Create a list of node names from those strings */ +- char *node_inc[count]; +- +- debug("Hash nodes (%d):\n", count); +- found_config = false; +- for (name = prop, i = 0; name < end; name += strlen(name) + 1, i++) { +- debug(" '%s'\n", name); +- node_inc[i] = (char *)name; +- if (!strncmp(FIT_CONFS_PATH, name, strlen(FIT_CONFS_PATH)) && +- name[sizeof(FIT_CONFS_PATH) - 1] == '/' && +- !strcmp(name + sizeof(FIT_CONFS_PATH), config_name)) { +- debug(" (found config node %s)", config_name); +- found_config = true; +- } +- } +- if (!found_config) { +- *err_msgp = "Selected config not in hashed nodes"; ++ /* Build the node list from the config, ignoring hashed-nodes */ ++ count = fit_config_get_hash_list(fit, conf_noffset, ++ node_inc, IMAGE_MAX_HASHED_NODES, ++ hash_buf, sizeof(hash_buf)); ++ if (count < 0) { ++ *err_msgp = "Failed to build hash node list"; + return -1; + } + +diff --git a/doc/usage/fit/signature.rst b/doc/usage/fit/signature.rst +index 0804bffd..80373234 100644 +--- a/doc/usage/fit/signature.rst ++++ b/doc/usage/fit/signature.rst +@@ -353,20 +353,27 @@ meantime. + Details + ------- + The signature node contains a property ('hashed-nodes') which lists all the +-nodes that the signature was made over. The image is walked in order and each +-tag processed as follows: ++nodes that the signature was made over. The signer (mkimage) writes this ++property as a record of what was included in the hash. During verification, ++however, U-Boot does not read 'hashed-nodes'. Instead it rebuilds the node ++list from the configuration's own image references (kernel, fdt, ramdisk, ++etc.), since 'hashed-nodes' is not itself covered by the signature. The ++rebuilt list always includes the root node, the configuration node, each ++referenced image node and its hash/cipher subnodes. ++ ++The image is walked in order and each tag processed as follows: + + DTB_BEGIN_NODE + The tag and the following name are included in the signature +- if the node or its parent are present in 'hashed-nodes' ++ if the node or its parent are present in the node list + + DTB_END_NODE + The tag is included in the signature if the node or its parent +- are present in 'hashed-nodes' ++ are present in the node list + + DTB_PROPERTY + The tag, the length word, the offset in the string table, and +- the data are all included if the current node is present in 'hashed-nodes' ++ the data are all included if the current node is present in the node list + and the property name is not 'data'. + + DTB_END +@@ -374,7 +381,7 @@ DTB_END + + DTB_NOP + The tag is included in the signature if the current node is present +- in 'hashed-nodes' ++ in the node list + + In addition, the signature contains a property 'hashed-strings' which contains + the offset and length in the string table of the strings that are to be +diff --git a/test/py/tests/test_vboot.py b/test/py/tests/test_vboot.py +index 04fa59f9..817eb980 100644 +--- a/test/py/tests/test_vboot.py ++++ b/test/py/tests/test_vboot.py +@@ -362,10 +362,14 @@ def test_vboot(u_boot_console, name, sha_algo, padding, sign_options, required, + shutil.copyfile(fit, efit) + vboot_evil.add_evil_node(fit, efit, evil_kernel, 'kernel@') + +- msg = 'Signature checking prevents use of unit addresses (@) in nodes' ++ # fit_check_sign catches this via signature mismatch (the @ ++ # node is hashed instead of the real one) + util.run_and_log_expect_exception( + cons, [fit_check_sign, '-f', efit, '-k', dtb], +- 1, msg) ++ 1, 'Failed to verify required signature') ++ ++ # bootm catches it earlier, at fit_check_format() time ++ msg = 'Signature checking prevents use of unit addresses (@) in nodes' + run_bootm(sha_algo, 'evil kernel@', msg, False, efit) + + # Create a new properly signed fit and replace header bytes diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 7eaf721ca8..4b6d89ed4e 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -1,2 +1,4 @@ require u-boot-common.inc require u-boot-tools.inc + +SRC_URI += "file://CVE-2026-46728.patch" diff --git a/meta/recipes-bsp/u-boot/u-boot_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot_2024.01.bb index e412f503f1..7eaeed1004 100644 --- a/meta/recipes-bsp/u-boot/u-boot_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot_2024.01.bb @@ -12,4 +12,5 @@ SRC_URI += "file://CVE-2024-57254.patch \ file://CVE-2024-57258-3.patch \ file://CVE-2024-57259.patch \ file://CVE-2024-42040.patch \ + file://CVE-2026-46728.patch \ " From patchwork Wed Aug 26 08:12:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96422 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7E7BEC61DCB for ; Wed, 26 Aug 2026 08:13:26 +0000 (UTC) Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7652.1787732005343016241 for ; Wed, 26 Aug 2026 01:13:25 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=hcVOLj32; spf=pass (domain: cisco.com, ip: 173.37.142.89, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1127; q=dns/txt; s=iport01; t=1787732005; x=1788941605; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=sgct+espJd6WR7B/eAdWWsFk1nX91ZWA0leKexFjvxk=; b=hcVOLj32b1N5vMtpjIKPH8/9IUHU/gqWyeGRuqSIQ40D3vCGJu3Rb8kw Gzg/Udx45qD/D4FhEO5IB2hTPy/mbkdi50kJ9MatD7lsHGUS+d7aErZmi HAExqwMEwt3Hng463k9VqmrlbkNzKfFMFz9MCa/7G5VtYgaXwrJp4Fds0 XxICWpozv4JCQnrm0jtcFb7gD+rzVapN4Jfw56SGHrdT6EtWjhmrYfSLM a5OnskotYO/i5O4GWpbewaiOmZuoAKKPOMpdAwpZwYwXNYKCDOTmSHTbJ FN4qQgpHCwBsM6jmn0NDZw4RKGQdBz8aafLi5cR7MvLx74dAOKjS0RlgQ A==; X-CSE-ConnectionGUID: H2L+P6m0RVC6i5gBZ9an9g== X-CSE-MsgGUID: ZyYMhgU5QqauaJBcPajY+Q== X-IPAS-Result: A0BDAgC6n45q/4wQJK1aHgEBCxIMggULgld0X0JJlk2eG4F+DwEBAQ9EDQQBAYUFAo1sAiY0CQ4BAgQDAgMBAQEBAQEBAQEBAQsBAQUBAQECAQcFgQ4Thk8NhlsCAQMyAUYQIDErKxmDA4J0AgERvwaCLIEBg2gCQ1DbMAELFAEFgTOFP4gidQGEfCcbG4FygUeDN4EFgVwBAYIthXgEgiKBDJNiSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQQIxk2fIEJXoErKWABEheBCYIHAoJaggUCAUlDDgdHPgsYDUgRLDcUGQQ+bgeOax+CSVo0LASBf6YfoQ8KKIN2jCKVVDOqbAuYfY4KllCEaYFoPIFHCwdwFYMiCUoZD444g2uBf8o6JDU9AQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:5m+XXqILxprsFo5OFE+RhpQlxSXFcZb7ZxGr2PjKsXjdYENS12EAm 2oXCz2GOv3ZZmqjct1ybIzipEkE75SHyt9gSAUd+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZsCCSa/kvxWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnQ0 T/Oi5eHYgH9i2Qqajt8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1OVmV1BdMdotxJKj9Pq PMyGmEEaEGM0rfeLLKTEoGAh+wqKM3teYdasXZ6wHSBVrAtQIvIROPB4towMDUY358VW62AI ZNHL2MzNHwsYDUXUrsTIJIinO6rj2PXeDxDo1XTrq0yi4TW5Fwoj+K9aIKPI7RmQ+1nj3e9p m37ol3gCwwTFvaU8TOHwzGV07qncSTTHdh6+KeD3vlyjVuew2YeBBEbWR6wpuO0okq/QM5Eb UsM9ywjqKI/+ECmQp/6RRLQnZKflhcYX9wVF6gx7xuAj/KPpQ2YHWMDCDVGbbTKqfMLeNDj7 XfR9/uBONClmOT9pa61nltMkQ6PBA== IronPort-HdrOrdr: A9a23:UwvUGK+F8KTam9S2PPduk+AAI+orL9Y04lQ7vn2ZhyY7TiX+rb HIoB11737JYVoqNU3I3OrwWpVoIkmskaKdn7NwAV7KZmCP0wGVxcNZnO7fKlbbdREWmNQw6U 5ISdkZNDSJNykYse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAY0++8YTzraXGfg2J9dOIEKK Y= X-Talos-CUID: 9a23:X9doIG4cc+8sj8NXS9ss1BQwWfh7dyXn8lyOIhK3I1Q4QbvERgrF X-Talos-MUID: 9a23:EaFPpgYdpMcF9eBThS7doTFtCZpR+q2zAWInmq0PufjHDHkl X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="817280021" Received: from alln-l-core-03.cisco.com ([173.36.16.140]) by alln-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:24 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-03.cisco.com (Postfix) with ESMTPS id 19E91180001EF; Wed, 26 Aug 2026 08:13:24 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id AD644CE1BBC; Wed, 26 Aug 2026 01:13:23 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 02/11] u-boot-tools: Ignore CVE-2024-42040 Date: Wed, 26 Aug 2026 01:12:51 -0700 Message-Id: <240b02378283bcfe760e1902a29fad5361fda380.1787731424.git.hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:26 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244329 From: Hetvi Thakar Analysis: - CVE-2024-42040 affects the U-Boot DHCP client in net/bootp.c [1]. - u-boot-tools uses tools-only_defconfig, where CONFIG_NET is disabled [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-42040 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 4b6d89ed4e..b5711e1f97 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -2,3 +2,5 @@ require u-boot-common.inc require u-boot-tools.inc SRC_URI += "file://CVE-2026-46728.patch" + +CVE_STATUS[CVE-2024-42040] = "not-applicable-config: DHCP client code in net/bootp.c is not built by tools-only_defconfig, which disables CONFIG_NET." From patchwork Wed Aug 26 08:12:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96423 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6748DC61DBD for ; Wed, 26 Aug 2026 08:13:36 +0000 (UTC) Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7694.1787732006576801565 for ; Wed, 26 Aug 2026 01:13:26 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=MnlN0ct+; spf=pass (domain: cisco.com, ip: 173.37.142.90, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1233; q=dns/txt; s=iport01; t=1787732006; x=1788941606; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=2r4dEc3lR6dMsxYQ2VHgxyw9+ri2teN5gHuoCpugxHs=; b=MnlN0ct+MTQhwxjvNSmx+etWQwImGBn/EwYX4SlUWFn1Ky3TFPa4fXzP KccCzlyuUYiM0zXye0Bif5zAGnXcCrhDyM8sgada6T+4/bejT5a5MH7tw oUHYsHlbhV3g4DsUpM8zhO3bA+UO/k4FgX4NsqSf/ks3xZnzD8ql1P8xV 0G2KCRcnCZJkh3B3H+p1vs1zmGcatF9tNZC3FTssihi3lwVYq0xeK4g/A VEnCRoxRl6N60nxO5nKJTuESrW760+QyGSdLklnBriwA/azbkbvEhdwgH qZWFPAF9ufen8pAWMeQT8hLdYKaYhbc/LNfq9fK86bdIEyEfPt/JtGzSO w==; X-CSE-ConnectionGUID: Cz7cV6FLT5+uFVYjcQUtvA== X-CSE-MsgGUID: H9FUlnw+S7u/O2jMQa5+pA== X-IPAS-Result: A0BDAgDBno5q/4oQJK1aglmCV3RfQkmWTZ4bgX4PAQEBDz0UBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NhlsCAQMyAUYQIDErKxmDA4J0AgERvnSCLIEBg2gCQ1DbMAELFAEFgTOFP4gidQGEfCcbG4FygUeDN4EFgVwBAYIthXgEgiKBDJNiSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQQIxk2fIEJXoErKWABEheBCYIHAoJaggUCAUlDDgdHPgsYDUgRLDcUGQQ+bgeOax+CSYEOLARMgTOmH6EPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:Kg7leqoYsovwnyBLt6tRH8dn1gheBmJPZBIvgKrLsJaIsI4StFCzt garIBmCOviKZTf3fowlaIjg8hgA7Z7QnN9qGgA6+3hkQSMQoOPIVI+TRqvS04x+DSFioGZPt Zh2hgzodZhsJpPkjk7zdOWn9T8jifHgqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYgLNNwJcaDpOtfrT8k035ZwehRtB1rAATaET1LPhvyF94KI3fcmZM3b+S49IKe+2L 86r5K255G7Q4yA2AdqjlLvhGmVSKlIFFVHT4pb+c/HKbilq/kTe4I5iXBYvQRs/ZwGyojxE4 I4lWapc5useFvakdOw1C3G0GszlVEFM0OevzXOX6aR/w6BaGpfh660GMa04AWEX0s1lXmpwq 9I8FG1Ocz69tuC9+Y+nVMA506zPLOGzVG8eknhkyTecCbMtRorOBv2To9RZxzw3wMtJGJ4yZ eJANmEpN0qGOkMJYwxHYH49tL/Aan3XcyFYoVGcv4I84nPYy0p6172F3N/9KofUGJ0PxxbHz o7A10SoLCweMsPc8mWYtVX2hMr2lH64QKtHQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHtlYM UE8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS4QWJzO/Qpg2eHGVBFmcHY909v8hwTjsvv rOUo+7U6fVUmOX9YRqgGn289Fte5QB9wbc+WBI5 IronPort-HdrOrdr: A9a23:RlkaeqEvF89pPgNUpLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:4QyYb21QNuKHwUG14Y8msbxfMdJ6eUOD4lPsfgylJ1hYSrasdEOO0fYx X-Talos-MUID: 9a23:U/ZH4w5jfkgE0VYB5DqFyrpnxoxIsoqTDEYS0q5Zpo6jby5VAj7AzyyeF9o= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="836502187" Received: from alln-l-core-01.cisco.com ([173.36.16.138]) by alln-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:25 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-01.cisco.com (Postfix) with ESMTPS id 8396D180008C9; Wed, 26 Aug 2026 08:13:25 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 20693CE1BBC; Wed, 26 Aug 2026 01:13:25 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 03/11] u-boot-tools: Ignore CVE-2024-57254 Date: Wed, 26 Aug 2026 01:12:52 -0700 Message-Id: <5378c262ed330809f6dbb9f81f3f8e4d2400de44.1787731424.git.hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244330 From: Hetvi Thakar Analysis: - CVE-2024-57254 affects U-Boot SquashFS runtime parsing [1]. - The tools-only build graph does not link fs/squashfs into its host tools [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-57254 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/tools/Makefile Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index b5711e1f97..2519dc521f 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -4,3 +4,4 @@ require u-boot-tools.inc SRC_URI += "file://CVE-2026-46728.patch" CVE_STATUS[CVE-2024-42040] = "not-applicable-config: DHCP client code in net/bootp.c is not built by tools-only_defconfig, which disables CONFIG_NET." +CVE_STATUS[CVE-2024-57254] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." From patchwork Wed Aug 26 08:12:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96428 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 64407C61DD3 for ; Wed, 26 Aug 2026 08:13:37 +0000 (UTC) Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7695.1787732007795918243 for ; Wed, 26 Aug 2026 01:13:27 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=h9BMSzO9; spf=pass (domain: cisco.com, ip: 173.37.142.91, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1361; q=dns/txt; s=iport01; t=1787732007; x=1788941607; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=9rJlBKvzXzedy2Ck0MbUJ5rZ3/4HMXpFWRmtg8POcNU=; b=h9BMSzO9W0vB3xxdJMa6fAz371oRSA8k4NUvXw8Z8AA7/nOtu/zlwAEF IP/w6zGDE28OxQWEwLmsyGuGT2EzPblORt1D022PYvKMDL2dORQWsXv0M SMXJ/jsAiS2HPS4g5Kb7W1CG78Fmdb0rtLfA4tBSSdmqNrvP562/7FnRV eMebZwvyRKU1qMLpfh+iTCA2sBuRYFZDNQ36yM1WIAc1hq/OhOBuvUKqv mvL/3U4oSGNEA567xhTUXFxlyaW7+02UCfuE+s7+32mAi5EdmGGQyvlkS eFAa2tMzcRs7r2OkZNtH8eN3jJh8fM0dqzcF0tpYZjiaqQXuO2iybIHzD Q==; X-CSE-ConnectionGUID: kgi+o2USTHWUX/4giRJSpg== X-CSE-MsgGUID: Oftuz6CQTUWruN/ulDwGtQ== X-IPAS-Result: A0BDAgDBno5q/4wQJK1aglmCV3RfQkmWTZ4bgX4PAQEBDz0UBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAgMSsrGYMDgnQCARG+dIIsgQGDaAJDUNswAQsUAQWBM4U/iCJ1AYR8JxsbgXKBR4M3gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJgQ4sBEynUqEPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:jrB/Ma2YpIgz9gAyRfbD5YRwkn2cJEfYwER7XKvMYLTBsI5bpzRRm DEXDG/VOayOZWGkKdF0PYm0/B5TsZfSmNQ2HgU63Hw8FHgiRegpqji6wuYcGwvIc6UvmWo+t 512huHodZ5yFjmH4E/xbtANlFEkvYmQXL3wFeXYDS54QA5gWU8JhAlq8wIDqtYAbeORXUXX5 Lsen+WFYAX7g24ubDpNg06+gEoHUMra6WtwUmMWPZinjHeG/1EJAZQWI72GLneQauF8Au6gS u/f+6qy92Xf8g1FIovNfmHTKxBirhb6ZGBiu1IOM0SQqkEqSh8ajs7XAMEhhXJ/0F1lqTzeJ OJl7vRcQS9xVkHFdX90vxNwS0mSNoUekFPLzOTWXcG7lyX7n3XQL/pGD043fopCx91LIV5zx btEJzE3TCubiLfjqF67YrEEasULJc3vOsYb/3pn1zycVa1gSpHYSKKM7thdtNsyrpkRRrCFO YxAN3w2MEyojx5nYj/7DLo+gOehhXDlWzZZs1mS46Ew5gA/ySQhiuC0aIuLJoziqcN9uUiEu 3CY1F3FPy4AKfrY1D6p7V2wv7qa9c/8cMdIfFGizdZtmFCVy2kZBREaWFf+qv6jh2a6WslDM AoT4icooK04+UCnQ9W7WAe3yENopTYVX95WVul/4waXx++MuECSB3MPSXhKb9lOWNIKeAHGH 2Shx7vBbQGDepXMIZ5B3t94dQ+PBBU= IronPort-HdrOrdr: A9a23:9Mv9lKAhVf4wlrPlHel055DYdb4zR+YMi2TDGXofdfUzSL3+qy nAppUmPHPP5Qr5HUtQ++xoW5PwJU80i6QU3WB5B97LN2PbUSmTXeRfBODZrQEIdReTygd179 YHT0EHMqySMXFKyeDn/QK/D9EshPOD8KyumKPi6k0Fd3ASV0mlhD0JcTpy1SZNNXF7OaY= X-Talos-CUID: 9a23:W7Md12vH7obc7YqDGyj1RAQI6IsmfXyeyy3tGHOYNltZD+GaSGWyw7trxp8= X-Talos-MUID: 9a23:96C7hARaU145gsy1RXTLii1/JplD2piTN1oQt9Ibv+WbGjBJbmI= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="820109648" Received: from alln-l-core-03.cisco.com ([173.36.16.140]) by alln-iport-4.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:27 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-03.cisco.com (Postfix) with ESMTPS id E2C48180001DD; Wed, 26 Aug 2026 08:13:26 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 87CAECE1BBC; Wed, 26 Aug 2026 01:13:26 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 04/11] u-boot-tools: Ignore CVE-2024-57255 Date: Wed, 26 Aug 2026 01:12:53 -0700 Message-Id: X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244331 From: Hetvi Thakar Analysis: - CVE-2024-57255 affects U-Boot SquashFS runtime parsing [1]. - The tools-only build graph does not link fs/squashfs into its host tools [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-57255 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/tools/Makefile Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 2519dc521f..6516d7698a 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -5,3 +5,4 @@ SRC_URI += "file://CVE-2026-46728.patch" CVE_STATUS[CVE-2024-42040] = "not-applicable-config: DHCP client code in net/bootp.c is not built by tools-only_defconfig, which disables CONFIG_NET." CVE_STATUS[CVE-2024-57254] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." +CVE_STATUS[CVE-2024-57255] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." From patchwork Wed Aug 26 08:12:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96429 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8A20CC61DCD for ; Wed, 26 Aug 2026 08:13:37 +0000 (UTC) Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7696.1787732009352537141 for ; Wed, 26 Aug 2026 01:13:29 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=ba2UBDZv; spf=pass (domain: cisco.com, ip: 173.37.142.95, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1502; q=dns/txt; s=iport01; t=1787732009; x=1788941609; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Hh9mz8YbAJahmBoU5fAAmn90gphsLFjf2uKA/lNtZRI=; b=ba2UBDZvCxXwHzv9TLJBMRaN9V8eY1rtjZxeOdudNwJD8HnnC1sizHPR mcJtRYVzwd4amZOW4xFMDhIyc2KM9ywqeSC8eXH/Yr2N4HPY95qY+j8HN AbvbTpmpD8B+vtGiQ+IiuN9vag1RsEF9+wo9EiwLyCGdS5kDWwpFCPX0P Wr1uWRXD5xF7c2UypgeXYmTMBXeUNeG/8xM/XNOlSxAQCo5/swQZwx6YK hKbheoxTEzZUvtmzZIODQYC+A2oomgn7zX4ATZ0GDI8E7FrWoDenCPxMT efFCUIlZ/sCgMocPo4ioMAWyNW3yW43F7JXxkPGsWWnIGhJpAxscsHsOG w==; X-CSE-ConnectionGUID: NDSZqmRUS3OpPlPy7xQrrg== X-CSE-MsgGUID: 6mUZUNqAThuMUlpHKxP65w== X-IPAS-Result: A0BDAgA+n45q/4oQJK1aglmCV3RfQkmWTZ4bgX4PAQEBDz0UBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAgMSsrGYMDgnQCARG+fIIsgQGDaAJDUNsvAQsUAQWBM4U/iCJ1AYR8JxsbgXKBR4M3gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJgQ4sBEynUqEPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:qnbp3qNSxBslbBfvrR3ylsFynXyQoLVcMsEvi/4bfWQNrUpx0mMGx 2YZWDqAMvbcYmv3KthwbYq390kPv5aHy4I2HnM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeaphyFTmE+kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf1gWAsawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj69NCN3MvOLclwb1QGVlKz e1HOAkXdB/W0opawJrjIgVtrs0nKM+uOMYUvWttiGmAS/0nWpvEBa7N4Le03h9p2ZsIRqiYP pRfMGE/BPjDS0Un1lM/CI4+leShnFH0ciZTrxSeoq9fD237nFYoiOizbIGIEjCMbZtQo3Slg Hvvw2TkJyweLPy82QLbr23504cjmgu+Aur+DoaQ8eZnhlCWzGEfBBAaEFC8u/SRjk+lR8kZL FQZ/Ccrp6U++EGnCN7nUHWFTGWstxoYXZ9UVuY98gzIkvOS6AeCDW9CRTlEADA7iPILqfUR/ gfht7vU6fZH6dV5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:rvUwV6BJzPMuT+zlHel055DYdb4zR+YMi2TDGXofdfUzSL3+qy nAppUmPHPP5Qr5HUtQ++xoW5PwJU80i6QU3WB5B97LN2PbUSmTXeRfBODZrQEIdReTygd179 YHT0EHMqySMXFKyeDn/QK/D9EshPOD8KyumKPi6k0Fd3ASV0mlhD0JcTpy1SZNNXF7OaY= X-Talos-CUID: 9a23:K4GT0G0M5hndIl1WUnhiurxfPOweQGTY9krreGigMWJRWeKFcEWK9/Yx X-Talos-MUID: 9a23:qLhhFAZKWS+v5OBT6TrRtgxELe5U47mLNUQVsbYWg5fZKnkl X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="821086435" Received: from alln-l-core-01.cisco.com ([173.36.16.138]) by alln-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:28 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-01.cisco.com (Postfix) with ESMTPS id 6F3A8180003F6; Wed, 26 Aug 2026 08:13:28 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 1606ACE1BBC; Wed, 26 Aug 2026 01:13:28 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 05/11] u-boot-tools: Ignore CVE-2024-57256 Date: Wed, 26 Aug 2026 01:12:54 -0700 Message-Id: <54ac50ad1d952ee140ffa94524c6632afe609ccb.1787731424.git.hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244332 From: Hetvi Thakar Analysis: - CVE-2024-57256 affects U-Boot Ext4 runtime parsing [1]. - The tools-only build graph does not link fs/ext4 into its host tools [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-57256 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/tools/Makefile Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 6516d7698a..66e46fa7af 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -6,3 +6,4 @@ SRC_URI += "file://CVE-2026-46728.patch" CVE_STATUS[CVE-2024-42040] = "not-applicable-config: DHCP client code in net/bootp.c is not built by tools-only_defconfig, which disables CONFIG_NET." CVE_STATUS[CVE-2024-57254] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57255] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." +CVE_STATUS[CVE-2024-57256] = "not-applicable-config: Ext4 runtime code is not built or linked into the host tools produced by tools-only_defconfig." From patchwork Wed Aug 26 08:12:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96430 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A304FC61DD4 for ; Wed, 26 Aug 2026 08:13:37 +0000 (UTC) Received: from alln-iport-8.cisco.com (alln-iport-8.cisco.com [173.37.142.95]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7696.1787732009352537141 for ; Wed, 26 Aug 2026 01:13:30 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=PVNkjrm8; spf=pass (domain: cisco.com, ip: 173.37.142.95, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1552; q=dns/txt; s=iport01; t=1787732010; x=1788941610; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=OzICAlo09NN8WoEhejjI/Dg2g6jjGvb0fgbuRJq269g=; b=PVNkjrm8WgL+IqWP98bwJadmitfNFlovHaj4HpYlGc8CKfK2J6p6t6I3 vZjGNKnq25ZSWAriikRTIJ+RaI2S36QHFna/p5Kdt+SnnB8h59Yzdq7L5 8tghuLDZWo8YSC7lmh3e9V2Im8yY9aKSfJVoPrEIxefqqmT6O2RR5HUji nX4c20tVa2P1WxIrCf1nRroTaTZCA8mHYZopz/BFgWHWYdvBuGWGsaAIS XM1iHxTmeXJz0I1OhS8tydMkS3gqwWISOYD2X3Umwn88IoPHV7fbmbOcT FuTwM1EF4JSSsSHU/HwTSU4WdUYXUNMW0/qqdnDXuhb0PTiKy5vkAajSz Q==; X-CSE-ConnectionGUID: TLvVyAPhSnK/msAr81VSSg== X-CSE-MsgGUID: FjFLzhdMTA6vcKufL4lmbw== X-IPAS-Result: A0BDAgA+n45q/4oQJK1aglmCV3RfQkmWTZ4bgX4PAQEBDz0UBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAgMSsrGYMDgnQCARG+fIIsgQGDaAJDUNsvAQsUAQWBM4U/iCJ1AYR8JxsbgXKBR4M3gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJgQ4sBEynUqEPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:SXAfuqomwvfGMPgXgJb020CQLD5eBmJPZBIvgKrLsJaIsI4StFCzt garIBnTPfeMazDzKY0jPNi/9EkAv8KDxtJgGQdtrC8zEn4X8+PIVI+TRqvS04x+DSFioGZPt Zh2hgzodZhsJpPkjk7zdOCn9j8kif3gqoPUUIbsIjp2SRJvVBAvgBdin/9RqoNziLBVOSvV0 T/Ji5OZYgLNNwJcaDpOtfrT8k035ZwehRtB1rAATaET1LPhvyF94KI3fcmZM3b+S49IKe+2L 86r5K255G7Q4yA2AdqjlLvhGmVSKlIFFVHT4pb+c/HKbilq/kTe4I5iXBYvQRs/ZwGyojxE4 I4lWapc5useFvakdOw1C3G0GszlVEFM0OevzXOX6aR/w6BaGpfh660GMa04AWEX0tpTH19f3 MQYEzYuKRWYrvjmmYyAceY506zPLOGzVG8eknhkyTecCbMtRorOBv2To9RZxzw3wMtJGJ4yZ eJANmEpN0qGOkMJYwxHYH49tL/Aan3XcyFYoVGcv4I84nPYy0p6172F3N/9KobTHZULwhvEz o7A10r7LDUINNC69RPb7HmPm+HrwSf+Up1HQdVU8dYv2jV/3Fc7DwUbU1a+q/S1hkOyHtlYM UE8/is1sbN081SmSNT4VRC0rHOI+BkGVLJt//YS4QWJzO/Qpg2eHGVBFmcHY909v8hwTjsvv rOUo+7U6fVUmOX9YRqgGn289Fte5QB9wbc+WBI5 IronPort-HdrOrdr: A9a23:eEgD66v6BMal3eEdm0z/fX+Y7skDrtV00zEX/kB9WHVpmwKj+P xG+85rsiMc5wxxZJhNo7290ey7MBHhHP1OkO0s1MmZPDUO0VHAROoJ0WKh+UyEJ8SUzIBgPM lbH5SWIeeAa2SS9fyKgzWQIpIH3MSN9ryuiKP1yndgShwvVoRbhj0Jczpy1iZNNXJ77V1TLu vl2vZ6 X-Talos-CUID: 9a23:8uk8Nm/qRAm/sWOkTWuVv3IwBP40W0Xd93HzZEqjIHw5EYOuclDFrQ== X-Talos-MUID: 9a23:0qXyMQx7mNTFD6jIM5gRE3ok3IyaqIqsJmQfkZkjh+DaKydTJjm50DCySJByfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="821086454" Received: from alln-l-core-01.cisco.com ([173.36.16.138]) by alln-iport-8.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:29 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-01.cisco.com (Postfix) with ESMTPS id A8D9C180003E9; Wed, 26 Aug 2026 08:13:29 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 4ED75CE1BBC; Wed, 26 Aug 2026 01:13:29 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 06/11] u-boot-tools: Ignore CVE-2024-57257 Date: Wed, 26 Aug 2026 01:12:55 -0700 Message-Id: X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244333 From: Hetvi Thakar Analysis: - CVE-2024-57257 affects U-Boot SquashFS runtime parsing [1]. - The tools-only build graph does not link fs/squashfs into its host tools [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-57257 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/tools/Makefile Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 66e46fa7af..5bf2ca0f91 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -7,3 +7,4 @@ CVE_STATUS[CVE-2024-42040] = "not-applicable-config: DHCP client code in net/boo CVE_STATUS[CVE-2024-57254] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57255] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57256] = "not-applicable-config: Ext4 runtime code is not built or linked into the host tools produced by tools-only_defconfig." +CVE_STATUS[CVE-2024-57257] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." From patchwork Wed Aug 26 08:12:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96424 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 10516C61DC7 for ; Wed, 26 Aug 2026 08:13:37 +0000 (UTC) Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7698.1787732011952222668 for ; Wed, 26 Aug 2026 01:13:32 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=ii1kXvQ6; spf=pass (domain: cisco.com, ip: 173.37.142.89, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1599; q=dns/txt; s=iport01; t=1787732011; x=1788941611; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=O1vSNf442yNL5/8U/BEjIkoCqb70/Q7v/VHdcgyXPeQ=; b=ii1kXvQ6dJ2UebFxekNtCNHCvUEdYfWCTgeRCsPE19iaqS6KZc8rTaVC zTGMf0B0R0oxn0XPSqOHji9QxM7noy2vIEb6dMGctdjeOBgyjmh+rYKPV RSV6d9kGgWDXY7V57Ve3UgZCdzbVhpwvqMXnKqqGmfnsJSgoj+Fa2ZFrI jzLTGbzhBKuT/Q+HQFNHBKAmptEaoo0EWFn+sFWWgXnRRHBffbBTPiu4E 6tdt/gRCTtLqKfjHd7ZwdnMFXbFxd5NPuGr/Ejkchcni4ySkQXWanLbSg 4ITXDEqo4W+LMdMAxs6NLpvMOBSOyX6OsCldCVBgf7tg6hf8sMmaG8juH g==; X-CSE-ConnectionGUID: IUuYBfQ0TgW7wqOvD6COkA== X-CSE-MsgGUID: gJnolPXoQ/2F2KCreG6vgA== X-IPAS-Result: A0BEAgC6n45q/5UQJK1aglmCV3RfQkmWTZ4bgX4PAQEBDz0UBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAdAzErHQ4ZgwOCdAIBEb8GgiyBAYNoAkNQ2zABCxQBBYEzhT+IInUBhHwnGxuBcoFHgkF2gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJgQ4sBEynUqEPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:lRVakaIh+1fZlrdKFE+RhpQlxSXFcZb7ZxGr2PjKsXjdYENS0D0Gy GNMCmqOa/vZNGb0edAlaYi/8xwEu8TcmNJhSgod+CA2RRqmiyZq6fd1j6vUF3nPRiEWZBs/t 63yUvGZcoZsCCSa/kvxWlTYhSEU/bmSQbbhA/LzNCl0RAt1IA8skhsLd9QR2uaEuvDnRVnQ0 T/Oi5eHYgH9i2Qqajt8B5+r8XuDgtyj4Fv0gXRmDRx7lAe2v2UYCpsZOZawIxPQKqFIHvS3T vr017qw+GXU5X8FUrtJRZ6iLyXm6paLVeS/oiI+t5qK23CulQRuukoPD8fwXG8M49m/c3+d/ /0W3XC4YV9B0qQhA43xWTEAe811FfUuFLMqvRFTvOTLp3AqfUcAzN1PMVwHF4Mhotp4Pj5R7 NsGBG4mSROq0rfeLLKTEoGAh+wqKM3teYdasXZ6wHSAV7AtQIvIROPB4towMDUY358VW62AI ZNHL2MzPXwsYDUXUrsTIJIinO6rj2PXeDxDo1XTrq0yi4TW5Fwoj+K9aIONJrRmQ+1avECfo lr2+F2+WD9AF/eFxBXb7H2F07qncSTTHdh6+KeD3vlyjVuew2YeBBEbWR6wpuO0okq/QM5Eb UsM9ywjqKI/+ECmQp/6RRLQnZKflhcYX9wVF6gx7xuAj/OOpQ2YHWMDCDVGbbTKqfMLeNDj7 XfR9/uBONClmOf9pa61nltMkQ6PBA== IronPort-HdrOrdr: A9a23:4NbYqqBplshycC/lHel055DYdb4zR+YMi2TDGXofdfUzSL3+qy nAppUmPHPP5Qr5HUtQ++xoW5PwJU80i6QU3WB5B97LN2PbUSmTXeRfBODZrQEIdReTygd179 YHT0EHMqySMXFKyeDn/QK/D9EshPOD8KyumKPi6k0Fd3ASV0mlhD0JcTpy1SZNNXF7OaY= X-Talos-CUID: 9a23:lVq122glGgWmcuQ7OF/wZgiEuzJuU0DA/V3eGheEBlk2V6SyV3PO04Rnup87 X-Talos-MUID: 9a23:40g+Zgt/09us6lynrM2nixNkM8NQ06OXTxojy7YtocSrazJ/EmLI X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="817280104" Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:31 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id F32BB1800020D; Wed, 26 Aug 2026 08:13:30 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 98A41CE1BBC; Wed, 26 Aug 2026 01:13:30 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 07/11] u-boot-tools: Ignore CVE-2024-57258 Date: Wed, 26 Aug 2026 01:12:56 -0700 Message-Id: X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244334 From: Hetvi Thakar Analysis: - CVE-2024-57258 affects U-Boot runtime allocation and target code [1]. - The tools-only build does not link that runtime code into its host tools [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-57258 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/tools/Makefile Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 5bf2ca0f91..4b836fc989 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -8,3 +8,4 @@ CVE_STATUS[CVE-2024-57254] = "not-applicable-config: SquashFS runtime code is no CVE_STATUS[CVE-2024-57255] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57256] = "not-applicable-config: Ext4 runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57257] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." +CVE_STATUS[CVE-2024-57258] = "not-applicable-config: The U-Boot runtime allocator and affected target architecture code are not linked into the host tools produced by tools-only_defconfig." From patchwork Wed Aug 26 08:12:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96427 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C9A74C61DC4 for ; Wed, 26 Aug 2026 08:13:36 +0000 (UTC) Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7699.1787732013337054212 for ; Wed, 26 Aug 2026 01:13:33 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=b0Oh7eNw; spf=pass (domain: cisco.com, ip: 173.37.142.94, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1589; q=dns/txt; s=iport01; t=1787732013; x=1788941613; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=KVDQiPQEUdc+Ntafgh1M4DTHoChxLJidrgmAa9c3k0I=; b=b0Oh7eNw1EbMQDPX+TQgd/CITRqpWcx4JUSqtsznLIlfMZ+eT0izgrOl cTNfo2/PjCHjnfGB9g0rVRzGBdvFKx/jC3C+CDnC4xjI365xxXK65cQfW tIltUqGy9FOpIdDXmnBsHANoGSnzeNwd38dpeew5Zafv6TN0J3+P2ItXS E2fUl7tpEwYyXgqLxwASOme4lvJJicIKNS2HtOptpToKqNuiaqc9Iv9MC QV4HqKiAMr3Dnvpr7WSfMlzD3dW2PJCdh2+nIslZwrmn6SwUO2e1UT+21 4C5OpUlyJu+3gnjCMQ1FKAuyWGkskl33V2wmOokCfLcIFHyvb85XvfcKp A==; X-CSE-ConnectionGUID: BwvjvABfQMWe6iUGNlB7hw== X-CSE-MsgGUID: w4uFLM1kRZS19npRHWiBQQ== X-IPAS-Result: A0BEAgC6n45q/5UQJK1aglmCV3RfQkmWTZ4bgX4PAQEBDz0UBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAdAzErHQ4ZgwOCdAIBEb8GgiyBAYNoAkNQ2zABCxQBBYEzhT+IInUBhHwnGxuBcoFHgkF2gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJgQ4sBEynUqEPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:cvDkRaNxDTByhVLvrR3ylsFynXyQoLVcMsEvi/4bfWQNrUom1TRWz zceWm/UO/mJYTTyLdt2btyxpEJTvZXVy4MxTXM5pCpnJ55oRWUpJjg4wmPYZX76whjrFRo/h ykmQoCeaphyFTmE+kvF3oHJ9RFUzbuPSqf3FNnKMyVwQR4MYCo6gHqPocZh6mJTqYb/WV7lV e/a+ZWFZgf1gWAsawr41orawP9RlKWq0N8nlgRWicBj5Df2i3QTBZQDEqC9R1OQapVUBOOzW 9HYx7i/+G7Dlz91Yj9yuu+mGqGiaue60Tmm0hK6aYD76vRxjnBaPpIACRYpQRw/ZwNlMDxG4 I4lWZSYEW/FN0BX8QgXe0Ew/ypWZcWq9FJbSJSymZT78qHIT5fj699xEkMoFKcWw8NIDD9Py NM+LBpSbg/W0opawJrjIgVtrs0nKM+uOMYUvWttiGiDS/0nWpvEBa7N4Le03h9p2ZsIRqiYP pRfMGY+BPjDS0Un1lM/CI4+leShnFH0ciZTrxSeoq9fD237nFUgi+GyYIeNEjCMbdoJg2i8g zvFxVbCW0AcLOa/9juvy0v504cjmgu+Aur+DoaQ8eZnhlCWzGEfBBAaEFC8u/SRjk+lR8kZL FQZ/Ccrp6U++EGnCN7nUHWFTGWstxoYXZ9UVuY98gzIk/CS6AeCDW9CRTlEADA7iPILqfUR/ gfht7vU6fZH6dV5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:gEY+aaAuvnXT2fflHel055DYdb4zR+YMi2TDGXofdfUzSL3+qy nAppUmPHPP5Qr5HUtQ++xoW5PwJU80i6QU3WB5B97LN2PbUSmTXeRfBODZrQEIdReTygd179 YHT0EHMqySMXFKyeDn/QK/D9EshPOD8KyumKPi6k0Fd3ASV0mlhD0JcTpy1SZNNXF7OaY= X-Talos-CUID: 9a23:5aVYJWORbYwTSO5DcjZ59lA9MM4cV0LQknbtDGm8IzlpV+jA X-Talos-MUID: 9a23:P6kBtQncWg/7NED4XTXqdnp9aNpGx4H3C3o/qsxXvdG+FRNxEQ6k2WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="819317850" Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:32 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id 730841800085D; Wed, 26 Aug 2026 08:13:32 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 1749BCE1BBC; Wed, 26 Aug 2026 01:13:32 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 08/11] u-boot-tools: Ignore CVE-2024-57259 Date: Wed, 26 Aug 2026 01:12:57 -0700 Message-Id: <06c1bea59c9793ee9e9418663819551578148b27.1787731424.git.hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244335 From: Hetvi Thakar Analysis: - CVE-2024-57259 affects U-Boot SquashFS runtime parsing [1]. - The tools-only build graph does not link fs/squashfs into its host tools [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2024-57259 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/tools/Makefile Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 4b836fc989..898b808063 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -9,3 +9,4 @@ CVE_STATUS[CVE-2024-57255] = "not-applicable-config: SquashFS runtime code is no CVE_STATUS[CVE-2024-57256] = "not-applicable-config: Ext4 runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57257] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57258] = "not-applicable-config: The U-Boot runtime allocator and affected target architecture code are not linked into the host tools produced by tools-only_defconfig." +CVE_STATUS[CVE-2024-57259] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." From patchwork Wed Aug 26 08:12:58 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96425 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EA314C61DCB for ; Wed, 26 Aug 2026 08:13:36 +0000 (UTC) Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7699.1787732013337054212 for ; Wed, 26 Aug 2026 01:13:34 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=TrrTy8oT; spf=pass (domain: cisco.com, ip: 173.37.142.94, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1604; q=dns/txt; s=iport01; t=1787732014; x=1788941614; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=buZe+K+gLh15VXrXZi2hZyOPsGAsi1b5PGabQXRhVlQ=; b=TrrTy8oT8T6rkIpB4cZR26dpXkP7Lungo3E8+9AKarBCxkiGuWbTl+4Q ZPbsfQrMPyFUdpbgTCV0EmdffbAp48FeWICx4hEbix7ulc3uY2AeAYwFc cjRBq9tA4QEFAt04fmH7/vLDOgD80L4PGyDKNNdg7LXeBNbuMvap1qoI/ nuF0a22fOa5Z+AmQecDhnrWVSq+OoDOUyODh5yG1wNDVgHjhM8Pyi1lIT E5BOXbsDwApjxkldnlVizmZseseJQwmMAWsIhELCEcn5Ebj2FuE8boQGI Okabjlw01J5xHb9T4DTTz8QkUiaZxWUItdIpWsKQBTwsEF7yL1uL+vrea Q==; X-CSE-ConnectionGUID: M8wiaOeYSeK9E5XY1p20xA== X-CSE-MsgGUID: n+MvKA80S1uAf3otviAZqg== X-IPAS-Result: A0BEAgC6n45q/5UQJK1aglmCV3RfQkmWTZ4bgX4PAQEBD0QNBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAdAzErHQ4ZgwOCdAIBEb8GgiyBAYNoAkNQ2zABCxQBBYEzhT+IInUBhHwnGxuBcoFHgkF2gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJWjQsBKgeoQ8KKIN2jCKVVDOqbAuYfY4KllCEaYFoPIFHCwdwFYMiCUoZD444g2uBf8o6JDU9AQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:atLnHKxxT/j+vB+3fCN6t+dgxyrEfRIJ4+MujC+fZmUNrF6WrkUEm zZNUGuBP/jbNmOmf4sjPonipBwHsZHXzNA3TAU/q1hgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCea/VH1buSJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 46aT/H3Ygf/hWYkaDxMsspvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJGRmIowR3etGOmxtp NFFGAFUdkrbl8vjldpXSsE07igiBMDvOIVavjRryivUSK98B5vCWK7No9Rf2V/chOgXQq2YP JRfMGQpNUiRC/FMEg9/5JYWnPuoj3r2aRVTqUmeouw85G27IAlZgOG8a4OKKoLaLSlTtkDbg 3zl1jShOUgHHdLEziab81uen+CayEsXX6pXTtVU7MVCh0WewGEWAhAaWVa35PK+kEOWX9NEN 1dS/TIjq6U3/kGnQtTxGRqirxa5UgU0Ut5UFag+rQqK0KeRulzfDWkfRTkHY9sj3CMreQEXO payt4uBLVRSXHe9ExpxKp/8QeuOBBUo IronPort-HdrOrdr: A9a23:2fFkoa/uxjRmIV/2hDpuk+AAI+orL9Y04lQ7vn2ZhyY7TiX+rb HIoB11737JYVoqNU3I3OrwWpVoIkmskaKdn7NwAV7KZmCP0wGVxcNZnO7fKlbbdREWmNQw6U 5ISdkZNDSJNykYse/KpC+lDt0n3N6LtIqshevY0jNRaDsCUdAY0++8YTzraXGfg2J9dOIEKK Y= X-Talos-CUID: 9a23:Rb+pZmh3X70sQAA7r0p89VwaIzJuVy3CzX73Ln6DBEU4ZeCleAaIovt0up87 X-Talos-MUID: 9a23:gjRMwgzhykrV0eTpRzsca8PjH3WaqKLtLV4uuMVegJCZHCIrPCuDjR2FW4Byfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="819317868" Received: from alln-l-core-12.cisco.com ([173.36.16.149]) by alln-iport-7.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:33 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-12.cisco.com (Postfix) with ESMTPS id B26971800020D; Wed, 26 Aug 2026 08:13:33 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 4F4F9CE1BBC; Wed, 26 Aug 2026 01:13:33 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 09/11] u-boot-tools: Ignore CVE-2026-29007 Date: Wed, 26 Aug 2026 01:12:58 -0700 Message-Id: X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-12.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244336 From: Hetvi Thakar Analysis: - CVE-2026-29007 affects U-Boot TCP processing in net/tcp.c [1]. - u-boot-tools uses tools-only_defconfig, where CONFIG_NET is disabled [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 898b808063..b13135c4de 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -10,3 +10,4 @@ CVE_STATUS[CVE-2024-57256] = "not-applicable-config: Ext4 runtime code is not bu CVE_STATUS[CVE-2024-57257] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57258] = "not-applicable-config: The U-Boot runtime allocator and affected target architecture code are not linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57259] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: TCP runtime code in net/tcp.c is not built by tools-only_defconfig, which disables CONFIG_NET." From patchwork Wed Aug 26 08:12:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96426 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4752BC61DD2 for ; Wed, 26 Aug 2026 08:13:37 +0000 (UTC) Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.7698.1787732011952222668 for ; Wed, 26 Aug 2026 01:13:35 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=Zv2vJkoQ; spf=pass (domain: cisco.com, ip: 173.37.142.89, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1617; q=dns/txt; s=iport01; t=1787732015; x=1788941615; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=64F4gh28UrgzIyrWhay/+mz4dHE8Tx0zdqW/20uKBlA=; b=Zv2vJkoQ4oFcq3Mz+pLjxBWysW5I7s3VhqjjqFz4y2eiUQje8bxG8xgy sRaWze/pXos6wJ6kwS9boVB0yFPZZe766T4Cw1g8Sk1wPNkmKKHVY2pAt 8CvmQqVx88kUEW1ohk8hMSnJQEaBWJ5umEgQmIAHWnWH4ySCD9TLi2XWz xbLN5MTSzxdPoVbO3EyYxCfUF6nZegR7VcW4IKQRDEBUQSeWhk1yceswq I6X8YuET7LjqirPfl8hLA93kydOPg63wJxLl+3uvexKu90eHZV3XPQ+JI qezU0rQrSKaKbPrmGRd0MTsROqpBVGD0+UVUvZEfIivDzS1pk+TtZLFji w==; X-CSE-ConnectionGUID: aYwv86AdTSa+WSl2I09A7Q== X-CSE-MsgGUID: XwTMTumnSsCn5er24+a8qw== X-IPAS-Result: A0BEAgC6n45q/5QQJK1aglmCV3RfQkmWTZ4bgX4PAQEBD0QNBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2GWwIBAzIBRhAdAzErHQ4ZgwOCdAIBEb8GgiyBAYNoAkNQ2zABCxQBBYEzhT+IInUBhHwnGxuBcoFHgkF2gQWBXAEBgi2FeASCIoEMk2JIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQ0bBgWBHYEohBAjGTZ8gQlegSspYAESF4EJggcCglqCBQIBSUMOB0c+CxgNSBEsNxQZBD5uB45rH4JJWjQsBIFkpjqhDwoog3aMIpVUM6psC5h9jgqWUIRpgWg8gUcLB3AVgyIJShkPjjiDa4F/yjokNT0BAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:VxlCGKxS6T1HUm/0nUB6t+dgxyrEfRIJ4+MujC+fZmUNrF6WrkVWm zcWUWCOb6nZY2r1KNsjaY63p0gA65aBnNRlSgBq/lhgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCea/VH1buSJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 46aT/H3Ygf/hWYkaDxMsspvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJEgHIpNIpM97PVpHt sMjLGosNkGq2NvjldpXSsE07igiBMDvOIVavjRryivUSK9/B5vCWK7No9Rf2V/chOgXQq2YP JRfMGQpNUiQC/FMEg9/5JYWnPuoj3r2aRVTqUmeouw85G27IAlZgOGyaoqNI4HWLSlTtnaHm kf64mH/OQoxMoGS02DZsXv8n/CayEsXX6pXTtVU7MVCh0WewGEWAhAaWVa35PK+kEOWX9NEN 1dS/TIjq6U3/kGnQtTxGRqirxa5UgU0Ut5UFag+rQqK0KeRul/fDWkfRTkHY9sj3CMreQEXO payt4uBLVRSXHe9EBpxKp/8QeuOBBUo IronPort-HdrOrdr: A9a23:6/yRl6HBB6NrjuDRpLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:XxN0H2vn5u7kFjYph+QGsk8T6IssQ2LDnCn5L3ODACVWc7nPaAfB0fxdxp8= X-Talos-MUID: 9a23:2HzFXQwNOnTDi6e4J3wZ6C2+4zOaqJSxNGUxjJAAgNKvM3F9IW3Bzz3nW5Byfw== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="817280154" Received: from alln-l-core-11.cisco.com ([173.36.16.148]) by alln-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:35 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-11.cisco.com (Postfix) with ESMTPS id 4FF68180001F6; Wed, 26 Aug 2026 08:13:35 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id E7A29CE1BBC; Wed, 26 Aug 2026 01:13:34 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 10/11] u-boot-tools: Ignore CVE-2026-29008 Date: Wed, 26 Aug 2026 01:12:59 -0700 Message-Id: <8d311bbd764e6b47ab63d838639aa7aa48725bb9.1787731424.git.hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-11.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244337 From: Hetvi Thakar Analysis: - CVE-2026-29008 affects the U-Boot TCP receive state machine in net/tcp.c [1]. - u-boot-tools uses tools-only_defconfig, where CONFIG_NET is disabled [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29008 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index b13135c4de..8579e18d7b 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -11,3 +11,4 @@ CVE_STATUS[CVE-2024-57257] = "not-applicable-config: SquashFS runtime code is no CVE_STATUS[CVE-2024-57258] = "not-applicable-config: The U-Boot runtime allocator and affected target architecture code are not linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2024-57259] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2026-29007] = "not-applicable-config: TCP runtime code in net/tcp.c is not built by tools-only_defconfig, which disables CONFIG_NET." +CVE_STATUS[CVE-2026-29008] = "not-applicable-config: TCP runtime code in net/tcp.c is not built by tools-only_defconfig, which disables CONFIG_NET." From patchwork Wed Aug 26 08:13:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 96431 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9DC5AC61DBD for ; Wed, 26 Aug 2026 08:13:47 +0000 (UTC) Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.7655.1787732017439620324 for ; Wed, 26 Aug 2026 01:13:37 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=S3PQ5CjX; spf=pass (domain: cisco.com, ip: 173.37.142.90, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1641; q=dns/txt; s=iport01; t=1787732017; x=1788941617; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=7QgpkDGaF4WsA2esxhiZTb1/SvUBDwxIEhNyTCZZVQk=; b=S3PQ5CjXed7L3bAbVFFgk7D2/vFBWDo7s1jQxmCzb0L53Z881L0qTTIk miv+YQxWNPYVYGxT2FNOEMD/biJluxaoiV/DKKAElgLx+Pcg96vyF7iQT YLaCBtlIBo3WmwA0OD+wYZ2kxNlikpF+WPjCUdLWRa9by0me+L3M1B3c+ y2Ixm4tnGaWawV2SW2cVaeAQxMhlkTJe+SOSS7f/KpOIp8gEEDc7Q95rq FqAcC6ZUfSyGpip3E6S+AComypV/eo7qg75w2gek9BcfJDA6JJBPY4U/1 Z4YcnHSG9i2EYm4ReCVws5t4G2ogP4z+/wqDthB7KKZ2sHdYdeoEXVc5U Q==; X-CSE-ConnectionGUID: /eWAgnLmSIKLmnBuYPO8og== X-CSE-MsgGUID: wfytbb1hSoWNCvUiM/PDLA== X-IPAS-Result: A0BDAgDBno5q/5MQJK1aglmCV3RfQkmWTZ4bgX4PAQEBD0QNBAEBhQUCjWwCJjQJDgECBAMCAwEBAQEBAQEBAQEBAQoBAQUBAQECAQcFgQ4Thk8NhlsCAQMyAUYQIDErKxmDA4J0AgERvnSCLIEBg2gCQ1DbMAELFAEFgTOFP4gidQGEfCcbG4FygUeDN4EFgVwBAYIthXgEgiKBDJNiSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4ENGwYFgR2BKIQQIxk2fIEJXoErKWABEheBCYIHAoJaggUCAUlDDgdHPgsYDUgRLDcUGQQ+bgeOax+CSVo0LASoHqEPCiiDdowilVQzqmwLmH2OCpZQhGmBaDyBRwsHcBWDIglKGQ+OOINrgX/KOiQ1PQEBBwIHDgMLgWiRfgEB IronPort-Data: A9a23:qLLsh6/IxzLs3FPFBJxODrUD13+TJUtcMsCJ2f8bNWPcYEJGY0x3n GBNDGiDbqncZ2Sgftl0OYSxpEgD7MeGyN5kGwZs+C1EQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmB4E/rbeSxxZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mvyyHjEAX9gWAsYjhKs/vrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2lxMLIx9eBTBFpv1 tgdLhoQXyik1+W5lefTpulE3qzPLeHiOIcZ/3UlxjbDALN/GdbIQr7B4plT2zJYasJmRKmFI ZFHL2MxKk2cPHWjOX9PYH46tOe0hnD8eidwo1OOrq1x6G/WpOB0+Oi2boeNIIfWFK25mG6Hq HPa9W6gAiodC/q01weE1zWUqsvmyHaTtIU6UefQGuRRqFqLy2oeDRcbWVe2rbyyjVSzc9ZeM FAPvC02oK4/8UamQtXwU1u/unHsg/IHc9NUF+t/7ESGzbDZpl/BQGMFVTVGLtchsafaWAAX6 7NApPuxbRQHjVFfYSj1Gmu8xd9qBRUoEA== IronPort-HdrOrdr: A9a23:Z04uuaGda4Z5MHkxpLqEMMeALOsnbusQ8zAXPo5KJiC9Ffbo8P xG88576faZslsssTQb6LK90cq7MBfhHOBOgbX5VI3KNGKNhILrFvAG0WKI+VPd8kPFmtK1/J 0QFZSWcOeAbmRSvILd/BSyFcomzZ2s9aClgvqb8lJWJDsaEp2JK2xCe32m+oocfng/OaYE X-Talos-CUID: 9a23:yp66L2BqspwjO7H6E25qy2cbHOQgSVz+6HLWCVKJMUE5T7LAHA== X-Talos-MUID: 9a23:tnk/iwl1ST4/fiHOwVSEdnp9OtZ06a73CHsKrrMtpfSFEGtIFxO02WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,244,1779148800"; d="scan'208";a="836502349" Received: from alln-l-core-10.cisco.com ([173.36.16.147]) by alln-iport-3.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 26 Aug 2026 08:13:36 +0000 Received: from sjc-ads-4178.cisco.com (sjc-ads-4178.cisco.com [171.70.54.199]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "ciscoit-managed-infra-smtp-auth.cisco.com", Issuer "Internal Private TLS SubCA" (verified OK)) by alln-l-core-10.cisco.com (Postfix) with ESMTPS id 8C3EC18000165; Wed, 26 Aug 2026 08:13:36 +0000 (GMT) Received: by sjc-ads-4178.cisco.com (Postfix, from userid 1887505) id 3147CCE1BBC; Wed, 26 Aug 2026 01:13:36 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][scarthgap][Patch 11/11] u-boot-tools: Ignore CVE-2026-29009 Date: Wed, 26 Aug 2026 01:13:00 -0700 Message-Id: X-Mailer: git-send-email 2.35.6 In-Reply-To: References: MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: VERIFIED;sjc-ads-4178.cisco.com [171.70.54.199];TLSv1.3;TLS_AES_256_GCM_SHA384;256;ciscoit-managed-infra-smtp-auth.cisco.com X-Outbound-SMTP-Client: 171.70.54.199, sjc-ads-4178.cisco.com X-Outbound-Node: alln-l-core-10.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 08:13:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/244338 From: Hetvi Thakar Analysis: - CVE-2026-29009 affects nfs_readlink_reply() when CONFIG_CMD_NFS is enabled [1]. - u-boot-tools uses tools-only_defconfig, where CONFIG_NET is disabled and CONFIG_CMD_NFS is not enabled [2]. - Hence ignore this CVE for u-boot-tools; the exclusion is configuration-based. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29009 [2] https://github.com/u-boot/u-boot/blob/866ca972d6c3/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb index 8579e18d7b..b2c4275ab9 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2024.01.bb @@ -12,3 +12,4 @@ CVE_STATUS[CVE-2024-57258] = "not-applicable-config: The U-Boot runtime allocato CVE_STATUS[CVE-2024-57259] = "not-applicable-config: SquashFS runtime code is not built or linked into the host tools produced by tools-only_defconfig." CVE_STATUS[CVE-2026-29007] = "not-applicable-config: TCP runtime code in net/tcp.c is not built by tools-only_defconfig, which disables CONFIG_NET." CVE_STATUS[CVE-2026-29008] = "not-applicable-config: TCP runtime code in net/tcp.c is not built by tools-only_defconfig, which disables CONFIG_NET." +CVE_STATUS[CVE-2026-29009] = "not-applicable-config: NFS client runtime code is not built by tools-only_defconfig, which disables CONFIG_NET and does not enable CONFIG_CMD_NFS."