From patchwork Fri Sep 4 12:41:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 97298 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F12D1C79F85 for ; Fri, 4 Sep 2026 12:42:15 +0000 (UTC) Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12950.1788525725729000211 for ; Fri, 04 Sep 2026 05:42:05 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=SJ1g1Z7p; spf=pass (domain: cisco.com, ip: 173.37.142.89, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1070; q=dns/txt; s=iport01; t=1788525725; x=1789735325; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=bEEMsgGsl0q5MXIQEL1uu079V7DNIza/572/4tMHC/I=; b=SJ1g1Z7pIYrbtFfDI3WYcmX2SUXAZ3QBVEVmG+1tSE44eXcSQpT6tB1+ hOyUEsWoALr8AI/hZl2GL91iBtUvLqGHXwZEkzqiqlNwFPyj55jZXVVK6 QwheOQI9bwN3kjdF1lIp7abj9H+aMHJ7a+eTx49rRvEcPGS/ZgQtgpxsz rMi0mc5XrqlrGcRHsV/Bj0vYUEzFwScQxLQwqUD+DSoysy6aclLZ5pRCW vZBnlNWth8kx06mg0ibSqeG9lNwS8wm08pnCVGtPKbt/e8IkvQCfLFzWX 4K4obVWjVLCOp1LM9kufsQNnRx3D49G2XFe8T8MToKktvi0MvtE59pwBX w==; X-CSE-ConnectionGUID: 8OrcP0KbSiOSWcKJbCvewg== X-CSE-MsgGUID: Wl5RdtKDQaufv9cpOMtS8w== X-IPAS-Result: A0BAAgBAu5pq/4wQJK1aglmCV3RgQ0m0aIF+DwEBAQ9EDQQBAYUFjgQCJjQJDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2QHzYBRjBcRIMCAYJ0AxHDIoIsgQGDaAJDUNsxAQsUAQWBM4U/iCJ1AYR8JxsbgXKEfoEFgVwBAYIthXgEgiKBDJNnSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BJ4M/Ixk2eoEJXoErKWABEheBCYIIAoJUggMCAUlDDgdHUwknQQQLGA1IESw3FRkEPm4Hjl8fglCBDiwEgX+mH6EPCiiDdowilToaM6ptC5h9jgqWUIRpgWg8gUcLB3AVgyIJShkPjjmDa4F/yjonMj0BAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:xIXXNq4zM08Hj6qM2mSYwQxRtG/GchMFZxGqfqrLsTDasY5as4F+v jNLWG7XM/3ZMGT2KN5yb9/lpBkP65fcnYRjT1c4qCE1Zn8b8sCt6fZ1gavT04J+CuWZESqLO u1HMoGowPgcFyGa/lH2dOC98RGQ7InQLpLkEunIJyttcgFtTSYlmHpLlvUw6mJSqYDR7zil5 5Wo/qUzBHf/g2QqajNMt/rawP9SlK2aVA0w7wRWic9j5Dcyp1FNZLoDKKe4KWfPQ4U8NoaSW +bZwbilyXjS9hErB8nNuu6TnpoiG+O60aCm0xK6aoD66vRwjnVaPpUTaJLwXXxqZwChxLid/ jniWauYEm/FNoWU8AgUvoIx/ytWZcWq85efSZSzXFD6I0DuKxPRL/tS4E4ebaoC8d4vImt19 NsjFzsuTBqome+pz+fuIgVsrpxLwMjDNYcbvDRkiDreF/tjGcuFSKTR7tge1zA17ixMNa+BP IxCN3w2MlKZP0Un1lQ/UPrSmM+omnn2cDRCgFmUvqEwpWPUyWSd1ZC9aoWKJozQGJQ9ckCwm WabxWjlIT0jPcGR12uO6lWJmtSfgnauMG4VPPjinhJwu3WU3mEVBRgcWFe3rPX8gUmkVvpbK lcI4WwptaU0+UmhQ9XxUhH+p2SL1iPwQPJZF+k8rQXIwa3O7kPBXS4PTyVKb5ots8peqSEW6 2JlVujBXVRH2IB5g1rHnltIhVte4RQoEFI= IronPort-HdrOrdr: A9a23:h6iaqqmKhcUTXN95ODzCYFL4yW/pDfIA3DAbv31ZSRFFG/FwWf rAoB19726QtN9/YhAdcLy7VZVoIkmsl6Kdn7NwAV7KZmCP0wGVxepZg7cKrQeNJ8TWzJ846U 4ZSdkcNPTASX5nkM39/A60V/wkwNWB7eSUoN229QYLcemvAJsQljuQzW2gYytLeDU= X-Talos-CUID: 9a23:yZ81eWOSL7xHU+5DCA59/3ZMOcoec1rm83zzAUWTF2t2R+jA X-Talos-MUID: 9a23:1H7nzAnbx0PLWpr0nwNzdnpdMJpS77iNJHkEjJsY6sKcEglsAGeC2WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,262,1779148800"; d="scan'208";a="827748259" Received: from alln-l-core-03.cisco.com ([173.36.16.140]) by alln-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Sep 2026 12:42:04 +0000 Received: from sjc-ads-5245.cisco.com (sjc-ads-5245.cisco.com [10.28.23.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-03.cisco.com (Postfix) with ESMTPS id C4E16180001F9; Fri, 4 Sep 2026 12:42:04 +0000 (GMT) Received: by sjc-ads-5245.cisco.com (Postfix, from userid 1887505) id 318BFCCD9B2; Fri, 4 Sep 2026 05:42:04 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][wrynose][PATCH 1/4] u-boot-tools: Ignore CVE-2026-29007 Date: Fri, 4 Sep 2026 05:41:54 -0700 Message-Id: <20260904124157.1723755-1-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5245.cisco.com [10.28.23.9];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.23.9, sjc-ads-5245.cisco.com X-Outbound-Node: alln-l-core-03.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 04 Sep 2026 12:42:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245098 From: Hetvi Thakar Analysis: - NVD identifies the vulnerable code as net/tcp.c when CONFIG_PROT_TCP is enabled [1]. - tools-only_defconfig disables networking, so this code is not built into u-boot-tools [2]. - Hence ignoring the CVE for this recipe. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007 [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 7eaf721ca83..0e57bb88849 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -1,2 +1,4 @@ require u-boot-common.inc require u-boot-tools.inc + +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." From patchwork Fri Sep 4 12:41:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 97299 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 09097C61DD6 for ; Fri, 4 Sep 2026 12:42:16 +0000 (UTC) Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12950.1788525725729000211 for ; Fri, 04 Sep 2026 05:42:07 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=e76PwEX8; spf=pass (domain: cisco.com, ip: 173.37.142.89, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1208; q=dns/txt; s=iport01; t=1788525727; x=1789735327; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=864sHBS0nhT7e79PqIGeItuWzUuGgEFHUIKiwDR8xfQ=; b=e76PwEX8hkJKXHshornknxBCMPXeVA0XEnntE44eLSPnFuOv6uxv3DDi 4IVWj/CZ9gS3DDE7x3eNI/43YzIAegaPomuwg67pISSkV2VAYWvXZ+EdO Bn9OeA+WHJMG6YVKGC3QjpaLjHF/MY8eu/0Z19hy25itO6hbqQPKq02Qt BtTU7kNeXa4VpO8kPuGgWcUKU4/orA5d/xzjOcX5v3tCq/rQUMf+18nVQ z8E0Lw+cdV0fhXWpiyvIk59f28FrGL4KZDxNpUncUheJpLI7jyFevFzv5 o5vq2Q+ROUJ6DBkPj4tBf/4Eun+5i3JD8nfxIUS02GoSw9asBtxLrEEA2 w==; X-CSE-ConnectionGUID: XB5BfqeRR6KEWTfRHy8cKQ== X-CSE-MsgGUID: ixeGLGE5StakdljiN0vhnQ== X-IPAS-Result: A0D5AgBAu5pq/5QQJK1aglmCV3RgQ0mWTZ4bgX4PAQEBD0QNBAEBhQUCjgICJjYHDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2QHQIBAzIBRhAgMSsrGYMCAYJ0AxHDIoIsgQGDaAJDUNsxAQsUAQWBM4U/iCJ1AYR8JxsbgXKEfoEFgVwBAYIthXgEgiKBDJNnSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BJ4M/Ixk2eoEJXoErKWABEheBCYIIAoJUggMCAUlDDgdHUwknQQQLGA1IESw3FRkEPm4Hjl8fglCBDiwEgX+mH6EPCiiDdowilToaM6ptC5h9jgqWUIRpgW8BNIFHCwdwFYMiCUoZD445g2uBf8o6JzI9AQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:WGugxq+LapZUz+T3QcUODrUD13+TJUtcMsCJ2f8bNWPcYEJGY0x3x zcbXWiBbPffMWGhfIskPd61801Vv8DRxoUyHAU4+XtEQiMRo6IpJzg2wmQcns+2BpeeJK6yx 5xGMrEsFOhtEDmE4EzrauS9xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4mvyyHjEAX9gWAsYzpIs/vrRC5H5ZwehhtJ5jTSWtgT1LPuvyF9JI4SI6i3M0z5TuF8dsamR /zOxa2O5WjQ+REgELuNyt4XpWVTH9Y+lSDX4pZnc/DKbipq/0Te4Y5nXBYoUnq7vh3S9zxHJ HqhgrTrIeshFvWkdO3wyHC0GQkmVUFN0OevzXRSLaV/wmWeG0YAzcmCA2kGF9Ay9P96O1sQ1 tEnFD43TgHTjMGPlefTpulE3qzPLeHiOIcZ/3UlxjbDALN/GNbIQr7B4plT2zJYasJmRKmFI ZFHL2MxKk2cM3WjOX9PYH46tOe0hnD8eidwo1OOrq1x6G/WpOB0+Oi3b4WJKobbHa25mG6Zt m/p20vUXyoGPd+TzTiE1Cqyhun2yHaTtIU6UefQGuRRqFqLy2oeDRcbWVe2rbyyjVSzc9ZeM FAPvC02oK4/8UamQtXwU1u/unHsg/IHc9NUF+t/7ESGzbDZpl/AQGMFVTVGLtchsafaWAAX6 7NApPuxbRQHjVFfYSv1Gmu8xd9qBRUoEA== IronPort-HdrOrdr: A9a23:sVeDKK0a/JJjxWbKCp3JOQqjBGokLtp133Aq2lEZdPWaSKOlfq eV7ZMmPHDP6Qr5NEtMpTnEAtjjfZq+z+8Q3WBuB9eftWDd0QPCRr2Kr7GSpgEIcBeRygcy78 tdmoFFebvN5CBB/KXHyTj9Nco8y9+a963tr+Lfw3BxCTxOUchbnn5E4sLxKDwMeOGAbqBJbK ah2g== X-Talos-CUID: 9a23:Fu+VGm0eIJ7K7xluZOTk6rxfKup4WHPEwU3qfWyVNlpncp2EGVSzwfYx X-Talos-MUID: 9a23:WcrbJwnzfH1OlxTdJflpdnpjJMpHx4uDVXsRmJYKv8uFE3RuOzGk2WE= X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,262,1779148800"; d="scan'208";a="827748290" Received: from alln-l-core-11.cisco.com ([173.36.16.148]) by alln-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Sep 2026 12:42:06 +0000 Received: from sjc-ads-5245.cisco.com (sjc-ads-5245.cisco.com [10.28.23.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-11.cisco.com (Postfix) with ESMTPS id B65E0180003B4; Fri, 4 Sep 2026 12:42:06 +0000 (GMT) Received: by sjc-ads-5245.cisco.com (Postfix, from userid 1887505) id 5CF9FCCD9B2; Fri, 4 Sep 2026 05:42:06 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][wrynose][PATCH 2/4] u-boot-tools: Ignore CVE-2026-29008 Date: Fri, 4 Sep 2026 05:41:55 -0700 Message-Id: <20260904124157.1723755-2-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260904124157.1723755-1-hthakar@cisco.com> References: <20260904124157.1723755-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5245.cisco.com [10.28.23.9];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.23.9, sjc-ads-5245.cisco.com X-Outbound-Node: alln-l-core-11.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 04 Sep 2026 12:42:16 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245099 From: Hetvi Thakar Analysis: - NVD identifies the vulnerable code as net/tcp.c when CONFIG_PROT_TCP is enabled [1]. - tools-only_defconfig disables networking, so this code is not built into u-boot-tools [2]. - Hence ignoring the CVE for this recipe. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29008 [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 0e57bb88849..6b28718c54a 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -2,3 +2,4 @@ require u-boot-common.inc require u-boot-tools.inc CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." +CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." From patchwork Fri Sep 4 12:41:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 97297 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id F0038C624DE for ; Fri, 4 Sep 2026 12:42:15 +0000 (UTC) Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.12950.1788525725729000211 for ; Fri, 04 Sep 2026 05:42:08 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=Ati6fN6W; spf=pass (domain: cisco.com, ip: 173.37.142.89, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=1337; q=dns/txt; s=iport01; t=1788525728; x=1789735328; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=LGdoNnr46nnq0oiMSw7OUUekkmUgs2aR09U5U/G2c2o=; b=Ati6fN6WpnTQqh6UJdOC78eIXjHIMAdSVPRdC4x7wH9MIR38xiRwXCeJ JWeAcAv9sIWQx3pF2rwUzdUGGhrxD+l410HlZNnDSTNfU/BQ0D1xllMxY 0Qf6vP3cFo1jRnFUhUK4b7U0G6r1oASbbxNfA68aeY8bP0eFZSBh+vGXR vFdLWo8Q0l/BsreeZGmIo5T0FBYAz1WxGh7MDW08RRJt1DLc0avgortQZ FqeUNmqXkpsxYCRlECCC7KnEcKyIH66pHEDqXkcFYR2BLXCg7Iz/DHIXK FY2Bby1FqX3OTplMW4s+hHY74078HpfTFzXnOIDyiqulz1ftQnab/QQN7 A==; X-CSE-ConnectionGUID: 55Ixb3k8RR+IctudS5HCTw== X-CSE-MsgGUID: gm/UUk+KTh+pygP4xeK92g== X-IPAS-Result: A0DFAgBAu5pq/5AQJK1aglmCV3RgQ0mWTZ4bgX4PAQEBD0QNBAEBhQUCjgICJjUIDgECBAMCAwEBAQEBAQEBAQEBCwEBBQEBAQIBBwWBDhOGTw2QHQIBAzIBRhAgMSsrGYMCAYJ0AxHDIoIsgQGDaAJDUNsxAQsUAQWBM4U/iCJ1AYR8JxsbgXKEfoEFgVwBAYIthXgEgiKBDJNnSIEeA1ksAVUTDQoLBwWBZgM1EioVbjIdgSM+F4EHGwYFgR2BJ4M/Ixk2eoEJXoErKWABEheBCYIIAoJUggMCAUlDDgdHUwknQQQLGA1IESw3FRkEPm4Hjl8fglCBDiwEgX+mH6EPCiiDdowilToaM6ptC5h9jgqWUIRpgWoDN4FHCwdwFYMiCUoZD445g2uBf8o6JzI9AQEHAgcOAwuBaJF+AQE IronPort-Data: A9a23:o+19U6z0TDneqUFwKHl6t+dgxyrEfRIJ4+MujC+fZmUNrF6WrkUPy jEZXm6HPPjeZDH9ettzPI6090gC6J7WnNUyTVNtq1hgHilAwSbn6Xt1DatR0we6dJCroJdPt p1GAjX4BJlqCCea/VH1buSJQUBUjcmgXqD7BPPPJhd/TAplTDZJoR94kobVuKYw6TSCK13L4 46aT/H3Ygf/hWYlaj5MsspvlTs21BjMkGJA1rABTagjUG/2zxE9EJ8ZLKetGHr0KqE8NvK6X evK0Iai9Wrf+Ro3Yvv9+losWhRXKlJ6FVHmZkt+A8BOsDAbzsAB+vpT2M4nVKtio27hc+adZ zl6ncfYpQ8BZsUgkQmGOvVSO3kW0aZuoNcrLZUj2CCe5xWuTpfi/xlhJBxrHJ0SoeUnO1sN1 PcENTw2MzCou/3jldpXSsE07igiBMDvOIVavjRryivUSK55B5vCWK7No9Rf2V/chOgXQq2YP JRfMGQpNUicC/FMEg9/5JYWnPuoj3r2aRVTqUmeouw85G27IAlZgOKyb4aFIYbSLSlTtkmd4 V/7/CfaPhFZLM2Q8WaV/1H93OCayEsXX6pXTtVU7MVCh0WewGEWAhAaWVa35PK+kEOWX9NEN 1dS/TIjq6U3/kGnQtTxGRqirxa5UgU0Ut5UFag+rQqK0KeRu1nfDWkfRTkHY9sj3CMreQEXO payt4uBLVRSXHe9EBpxKp/8QeuOBBUo IronPort-HdrOrdr: A9a23:Qsi/9K5p/+4ktcYJawPXwBDXdLJyesId70hD6qm+c3Nom6uj5q eTdZsgtCMc5Ax9ZJhko6HjBEDiewK5yXcK2+ks1N6ZNWGM0ldAbrsSiLcKqAePJ8SRzIJgPI 5bAs5D4aXLfDtHpPe/xhWkGNA9x9TC2qWpieDCi0pJd2hRGthdB8MTMHfhLqWwLzM2faYEKA == X-Talos-CUID: 9a23:3vyu0WgT2WdGYBjlW/qucQXfqjJuLyD83H2LIB+CMyVIQ6GIRWTN2IhYjJ87 X-Talos-MUID: 9a23:oIRWzAUgsfAXXE3q/DDpwwxfN4RL36TtEFECqckWturVbyMlbg== X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,262,1779148800"; d="scan'208";a="827748320" Received: from alln-l-core-07.cisco.com ([173.36.16.144]) by alln-iport-2.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Sep 2026 12:42:08 +0000 Received: from sjc-ads-5245.cisco.com (sjc-ads-5245.cisco.com [10.28.23.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-07.cisco.com (Postfix) with ESMTPS id 1FC71180001C1; Fri, 4 Sep 2026 12:42:08 +0000 (GMT) Received: by sjc-ads-5245.cisco.com (Postfix, from userid 1887505) id B9A07CCD9B2; Fri, 4 Sep 2026 05:42:07 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][wrynose][PATCH 3/4] u-boot-tools: Ignore CVE-2026-29009 Date: Fri, 4 Sep 2026 05:41:56 -0700 Message-Id: <20260904124157.1723755-3-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260904124157.1723755-1-hthakar@cisco.com> References: <20260904124157.1723755-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5245.cisco.com [10.28.23.9];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.23.9, sjc-ads-5245.cisco.com X-Outbound-Node: alln-l-core-07.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 04 Sep 2026 12:42:15 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245100 From: Hetvi Thakar Analysis: - NVD identifies the vulnerable code as the NFS client implementation enabled by CONFIG_CMD_NFS [1]. - tools-only_defconfig disables networking, so net/nfs.c is not built into u-boot-tools [2]. - Hence ignoring the CVE for this recipe. Reference: [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29009 [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig Signed-off-by: Hetvi Thakar --- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 6b28718c54a..5e2ed063868 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -3,3 +3,4 @@ require u-boot-tools.inc CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." +CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools." From patchwork Fri Sep 4 12:41:57 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" X-Patchwork-Id: 97300 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 19C3FC79F85 for ; Fri, 4 Sep 2026 12:42:36 +0000 (UTC) Received: from alln-iport-1.cisco.com (alln-iport-1.cisco.com [173.37.142.88]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.12810.1788525747901926096 for ; Fri, 04 Sep 2026 05:42:28 -0700 Authentication-Results: mx.groups.io; dkim=fail reason="dkim: message contains an insecure body length tag" header.i=@cisco.com header.s=iport01 header.b=Qfpm+dNA; spf=pass (domain: cisco.com, ip: 173.37.142.88, mailfrom: hthakar@cisco.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=4644; q=dns/txt; s=iport01; t=1788525747; x=1789735347; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=9wvlPz/KbW/kH+SbIeEW3cOvgPfl4gxQKyrkolMiQtk=; b=Qfpm+dNAEQO75dZLXa0bhuJhzqbDblW8iQ9pWuBUik4PxOGLWRu5KKrZ Jiax2cA/MGy6FLVknqw1scozal1zWo+Xl3QPZeGSPegelzHKqQPbxLCXD 8MTP1YJDz3lfbJg+JJU1oERgkYT1O1PLWgeP3gP47soRrr1rK0WFUDz6/ 1mp/Dwo7sHKGthJLIQxDFrHRgUtH08Xm4vOM0Ta+JKh2iMng/ffRYAuF/ nKbcFd4Yh78FykGRZa7zHS2D7QyK6wtLZ7QOvz9M+0tvHndVvQQnNtQOp uZGKOILj0rs4Q0LlCykzul3DdoXXB4YZce+ruL4P91zQqJv0tWi7QfSz0 Q==; X-CSE-ConnectionGUID: LMJWq0A8TumgyPag3KZAZw== X-CSE-MsgGUID: jUuvhQfCQbGaDSVhl3UZrg== X-IPAS-Result: A0AnAABYvJpq/4oQJK1QCh0BAQEBCQESAQUFAYF8CAELAYJWdGBDSQOMb4lYA54bFIFqDwEBAQ9EDQQBAYQ/RgKOAgImNAkOAQIEAwIDAQEBAQEBAQEBAQELAQEFAQEBAgEHBYEOE4ZPDZAdAgEDMgE0EhAdAzErHQ4ZgwIBgnQDEQbDEoIsgQGDaAJD3AEBCxQBBYEzAYU+iCJ2hHwnGxuBcoEVgnpvgQWBXAEBgTMThl8EgiKBDIQmj0FIgR4DWSwBVRMNCgsHBYFmAzUSKhVuMh2BIz4XgQcbBgWBHYEngz8jGTZ6gQlegSspYAESF4EJgggCglSCAwIBSUMOB0dTCSdBBAsYDUgRLDcVGQQ+bgeOXx+CAU9ZNQErBRuBXQYpk3yReqEPCiiDdowilToaM4QEpmmZCIJZizGVZxlQhGmBaDyBRwsHcBWDIgkKQBkPji4LCxyDRIF/gxTHJicyAgEIAy8BAQcCBw4DC4FokX4BAQ IronPort-Data: A9a23:yySLRaBry54YIRVW/3/iw5YqxClBgxIJ4kV8jS/XYbTApDMghTUFz mZJWGuGOv/fNmT8L413aN6wpE0FvsWHm4VrOVdlrnsFo1CmBibm6XV1Cm+qYkt+++WaFBoPA /02M4eGdIZvCCeA+n9BC5C5xVFkz6aEW7HgP+DNPyF1VGdMRTwo4f5Zs7ZRbrVA357jXmthh fuo+5eBYA79h2YtWo4pw/vrRC1H7ayaVAww5jTSVdgT1HfCmn8cCo4oJK3ZBxPQXolOE+emc P3Ixbe/83mx109F5gSNy+uTnuUiG9Y+DCDW4pZkc/HKbitq+kTe5p0G2M80Mi+7vdkmc+dZk 72hvbToIesg0zaldO41C3G0GAkmVUFKFSOuzXWX6aSuI0P6n3TE59BMM1huFN0k5+N4EFlH+ qc7Ghk/cUXW7w626OrTpuhEj8AnKozveYgYoHwllWifBvc9SpeFSKLPjTNa9G5v3YYVQ7CHO YxAMmoHgBfoO3WjPn8XFJI3n+6yrnL+aDZf7lmSoMLb5kCDl1EugeK1boK9ltqiR/hIgEahq En/9UvwLiokNNjE9Aif/Sf57gPItWahMG4IL5W/7vNsjViZy2AfBRFTXlyhrNG9i1WiQJRYM 0ES9y8koKQ++UDtScPyNyBUu1aNuhoaHt4VGOog5UTVk+zf4h2SAS4PSTsphMEaifLajAcCj jeh9+4FzxQ269V5lVr1Gm+okA6P IronPort-HdrOrdr: A9a23:C2sM5qznnEhPHCus/XSSKrPw9L1zdoMgy1knxilNoNJuHfBw8P re+8jzuiWUtN98YhwdcJW7Scu9qBDnhPpICPcqXYtKNTOO0ADDEGgh1/qG/9SKIUPDH4BmuZ uIWpIObuEYdWIK7vrS0U2fD8sqxsWB/eSDgOfTyGoocCRRApsQljuQzm2gYzZLrM4sP+tAKK ah X-Talos-CUID: 9a23:dPLNgGnQe9mdGA4qyFE1jRsus9nXOVn47kjJe2boNXtsR6ytQFDL25FNodU7zg== X-Talos-MUID: 9a23:hXr6twuOl104AAf3Ps2nhgx/KsdR7Y+XAm8Eva44u83fCB5qNGLI X-IronPort-Anti-Spam-Filtered: true X-IronPort-AV: E=Sophos;i="6.25,262,1779148800"; d="scan'208";a="835792060" Received: from alln-l-core-01.cisco.com ([173.36.16.138]) by alln-iport-1.cisco.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 04 Sep 2026 12:42:09 +0000 Received: from sjc-ads-5245.cisco.com (sjc-ads-5245.cisco.com [10.28.23.9]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by alln-l-core-01.cisco.com (Postfix) with ESMTPS id 99AC1180008E7; Fri, 4 Sep 2026 12:42:09 +0000 (GMT) Received: by sjc-ads-5245.cisco.com (Postfix, from userid 1887505) id 38F6ECCD9B2; Fri, 4 Sep 2026 05:42:09 -0700 (PDT) From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" To: openembedded-core@lists.openembedded.org Cc: xe-linux-external@cisco.com, Hetvi Thakar Subject: [OE-core][wrynose][PATCH 4/4] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Date: Fri, 4 Sep 2026 05:41:57 -0700 Message-Id: <20260904124157.1723755-4-hthakar@cisco.com> X-Mailer: git-send-email 2.35.6 In-Reply-To: <20260904124157.1723755-1-hthakar@cisco.com> References: <20260904124157.1723755-1-hthakar@cisco.com> MIME-Version: 1.0 X-Auto-Response-Suppress: DR, OOF, AutoReply X-Outbound-Client-TLS: ANONYMOUS;sjc-ads-5245.cisco.com [10.28.23.9];TLSv1.3;TLS_AES_256_GCM_SHA384;256 X-Outbound-SMTP-Client: 10.28.23.9, sjc-ads-5245.cisco.com X-Outbound-Node: alln-l-core-01.cisco.com List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 04 Sep 2026 12:42:36 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/245101 From: Hetvi Thakar CVE-2026-33243 is assigned to barebox, but NVD currently also maps it to denx:u-boot. That U-Boot mapping is incorrect because the U-Boot-side FIT hashed-nodes verification issue is tracked separately as CVE-2026-46728. A correction request has been sent to NVD to remove the incorrect denx:u-boot mapping. The existing patch backports U-Boot commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241 [3], which is the U-Boot fix referenced by CVE-2026-46728 [2]. Rename the patch and update its CVE tag so the filename and metadata identify the affected U-Boot vendor correctly. Apply the same patch to u-boot-tools because that recipe builds fit_check_sign, which uses the affected FIT signature-verification path. The bootloader recipe already carried the backport, but u-boot-tools did not. [1] https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4 [2] https://nvd.nist.gov/vuln/detail/CVE-2026-46728 [3] https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241 Signed-off-by: Hetvi Thakar --- .../{CVE-2026-33243.patch => CVE-2026-46728.patch} | 11 ++++++++--- meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 4 ++++ meta/recipes-bsp/u-boot/u-boot_2026.01.bb | 4 +++- 3 files changed, 15 insertions(+), 4 deletions(-) rename meta/recipes-bsp/u-boot/files/{CVE-2026-33243.patch => CVE-2026-46728.patch} (98%) diff --git a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch similarity index 98% rename from meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch rename to meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch index c7086e183fb..4e582d529ea 100644 --- a/meta/recipes-bsp/u-boot/files/CVE-2026-33243.patch +++ b/meta/recipes-bsp/u-boot/files/CVE-2026-46728.patch @@ -28,11 +28,16 @@ Closes: https://lore.kernel.org/u-boot/20260302220937.3682128-1-trini@konsulko.c Reported-by: Apple Security Engineering and Architecture (SEAR) Tested-by: Tom Rini -[YB: Removed a skippable condition in fit_config_get_hash_list. - This flag is not available in this version] -CVE: CVE-2026-33243 +CVE: CVE-2026-46728 Upstream-Status: Backport [https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241] + +Backport Changes: +Dropped the FIT_COMPAT_PROP condition because this macro is not +available in U-Boot v2026.01. + +(cherry picked from commit 2092322b31cc8b1f8c9e2e238d1043ae0637b241) Signed-off-by: Yanis Binard +Signed-off-by: Hetvi Thakar --- boot/image-fit-sig.c | 226 +++++++++++++++++++++++++++++------- doc/usage/fit/signature.rst | 19 ++- diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb index 5e2ed063868..77e086815c1 100644 --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb @@ -1,6 +1,10 @@ require u-boot-common.inc require u-boot-tools.inc +SRC_URI += "file://CVE-2026-46728.patch" + +CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport." + CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." CVE_STATUS[CVE-2026-29008] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools." CVE_STATUS[CVE-2026-29009] = "not-applicable-config: tools-only_defconfig disables networking; net/nfs.c is not compiled into u-boot-tools." diff --git a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb index 6d9bc126a16..9610d9e8fe0 100644 --- a/meta/recipes-bsp/u-boot/u-boot_2026.01.bb +++ b/meta/recipes-bsp/u-boot/u-boot_2026.01.bb @@ -3,7 +3,9 @@ require u-boot.inc DEPENDS += "bc-native dtc-native gnutls-native python3-pyelftools-native" -SRC_URI += "file://CVE-2026-33243.patch" +SRC_URI += "file://CVE-2026-46728.patch" + +CVE_STATUS[CVE-2026-33243] = "cpe-incorrect: NVD currently maps this CVE to denx:u-boot, but that mapping is incorrect for U-Boot; the U-Boot-side FIT issue is tracked separately as CVE-2026-46728 and is fixed by the included U-Boot backport." # workarounds for aarch64 kvm qemu boot regressions SRC_URI:append:qemuarm64 = " file://disable-CONFIG_BLOBLIST.cfg"