diff mbox series

[7/7] linux-yocto/6.6: update CVE exclusions

Message ID 9db4c02a9d59d428f7864902746e9e3195d4c16c.1707252636.git.bruce.ashfield@gmail.com
State Accepted, archived
Commit 20ceea5be17b64cbc95d36cc1afd5d41a2517500
Headers show
Series [1/7] linux-yocto/6.6: features/qat/qat.cfg: enable CONFIG_PCIEAER | expand

Commit Message

Bruce Ashfield Feb. 6, 2024, 8:53 p.m. UTC
From: Bruce Ashfield <bruce.ashfield@gmail.com>

Data pulled from: https://github.com/nluedtke/linux_kernel_cves

    1/1 [
        Author: Nicholas Luedtke
        Email: nicholas.luedtke@uwalumni.com
        Subject: Update 3Feb24
        Date: Sat, 3 Feb 2024 00:42:14 -0500

    ]

Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
---
 .../linux/cve-exclusion_6.6.inc               | 70 +++++++++++++++++--
 1 file changed, 64 insertions(+), 6 deletions(-)
diff mbox series

Patch

diff --git a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
index 9398434082..f3b3f32736 100644
--- a/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
+++ b/meta/recipes-kernel/linux/cve-exclusion_6.6.inc
@@ -1,9 +1,9 @@ 
 
 # Auto-generated CVE metadata, DO NOT EDIT BY HAND.
-# Generated at 2024-01-25 01:32:27.591716+00:00 for version 6.6.13
+# Generated at 2024-02-04 13:08:50.287438+00:00 for version 6.6.15
 
 python check_kernel_cve_status_version() {
-    this_version = "6.6.13"
+    this_version = "6.6.15"
     kernel_version = d.getVar("LINUX_VERSION")
     if kernel_version != this_version:
         bb.warn("Kernel CVE status needs updating: generated for %s but kernel is %s" % (this_version, kernel_version))
@@ -3668,6 +3668,10 @@  CVE_STATUS[CVE-2021-3348] = "fixed-version: Fixed from version 5.11rc6"
 
 CVE_STATUS[CVE-2021-33624] = "fixed-version: Fixed from version 5.13rc7"
 
+CVE_STATUS[CVE-2021-33630] = "fixed-version: Fixed from version 5.4rc1"
+
+CVE_STATUS[CVE-2021-33631] = "fixed-version: Fixed from version 6.2rc1"
+
 CVE_STATUS[CVE-2021-33655] = "fixed-version: Fixed from version 5.19rc6"
 
 CVE_STATUS[CVE-2021-33656] = "fixed-version: Fixed from version 5.12rc1"
@@ -4420,7 +4424,7 @@  CVE_STATUS[CVE-2022-3636] = "fixed-version: Fixed from version 5.19rc1"
 
 CVE_STATUS[CVE-2022-3640] = "fixed-version: Fixed from version 6.1rc4"
 
-# CVE-2022-36402 has no known resolution
+CVE_STATUS[CVE-2022-36402] = "fixed-version: Fixed from version 6.5"
 
 # CVE-2022-3642 has no known resolution
 
@@ -5100,8 +5104,12 @@  CVE_STATUS[CVE-2023-4622] = "fixed-version: Fixed from version 6.5rc1"
 
 CVE_STATUS[CVE-2023-4623] = "fixed-version: Fixed from version 6.6rc1"
 
+CVE_STATUS[CVE-2023-46343] = "fixed-version: Fixed from version 6.6rc7"
+
 CVE_STATUS[CVE-2023-46813] = "fixed-version: Fixed from version 6.6rc7"
 
+CVE_STATUS[CVE-2023-46838] = "cpe-stable-backport: Backported in 6.6.14"
+
 CVE_STATUS[CVE-2023-46862] = "fixed-version: Fixed from version 6.6"
 
 # CVE-2023-47233 has no known resolution
@@ -5112,10 +5120,14 @@  CVE_STATUS[CVE-2023-4881] = "fixed-version: Fixed from version 6.6rc1"
 
 CVE_STATUS[CVE-2023-4921] = "fixed-version: Fixed from version 6.6rc1"
 
-# CVE-2023-50431 has no known resolution
+CVE_STATUS[CVE-2023-50431] = "cpe-stable-backport: Backported in 6.6.14"
 
 CVE_STATUS[CVE-2023-5090] = "fixed-version: Fixed from version 6.6rc7"
 
+CVE_STATUS[CVE-2023-51042] = "fixed-version: Fixed from version 6.5rc1"
+
+CVE_STATUS[CVE-2023-51043] = "fixed-version: Fixed from version 6.5rc3"
+
 CVE_STATUS[CVE-2023-5158] = "fixed-version: Fixed from version 6.6rc5"
 
 CVE_STATUS[CVE-2023-51779] = "cpe-stable-backport: Backported in 6.6.9"
@@ -5130,6 +5142,8 @@  CVE_STATUS[CVE-2023-51782] = "cpe-stable-backport: Backported in 6.6.8"
 
 CVE_STATUS[CVE-2023-5197] = "fixed-version: Fixed from version 6.6rc3"
 
+CVE_STATUS[CVE-2023-52340] = "fixed-version: Fixed from version 6.3rc1"
+
 CVE_STATUS[CVE-2023-5345] = "fixed-version: Fixed from version 6.6rc4"
 
 CVE_STATUS[CVE-2023-5633] = "fixed-version: Fixed from version 6.6rc6"
@@ -5148,6 +5162,8 @@  CVE_STATUS[CVE-2023-6121] = "cpe-stable-backport: Backported in 6.6.4"
 
 CVE_STATUS[CVE-2023-6176] = "fixed-version: Fixed from version 6.6rc2"
 
+CVE_STATUS[CVE-2023-6200] = "cpe-stable-backport: Backported in 6.6.9"
+
 # CVE-2023-6238 has no known resolution
 
 # CVE-2023-6270 has no known resolution
@@ -5166,7 +5182,7 @@  CVE_STATUS[CVE-2023-6560] = "cpe-stable-backport: Backported in 6.6.5"
 
 CVE_STATUS[CVE-2023-6606] = "cpe-stable-backport: Backported in 6.6.9"
 
-# CVE-2023-6610 needs backporting (fixed from 6.7rc7)
+CVE_STATUS[CVE-2023-6610] = "cpe-stable-backport: Backported in 6.6.13"
 
 CVE_STATUS[CVE-2023-6622] = "cpe-stable-backport: Backported in 6.6.7"
 
@@ -5174,6 +5190,8 @@  CVE_STATUS[CVE-2023-6679] = "fixed-version: only affects 6.7rc1 onwards"
 
 CVE_STATUS[CVE-2023-6817] = "cpe-stable-backport: Backported in 6.6.7"
 
+CVE_STATUS[CVE-2023-6915] = "cpe-stable-backport: Backported in 6.6.13"
+
 CVE_STATUS[CVE-2023-6931] = "cpe-stable-backport: Backported in 6.6.7"
 
 CVE_STATUS[CVE-2023-6932] = "cpe-stable-backport: Backported in 6.6.5"
@@ -5188,5 +5206,45 @@  CVE_STATUS[CVE-2024-0340] = "fixed-version: Fixed from version 6.4rc6"
 
 CVE_STATUS[CVE-2024-0443] = "fixed-version: Fixed from version 6.4rc7"
 
-# Skipping dd=CVE-2023-1476, no affected_versions
+CVE_STATUS[CVE-2024-0562] = "fixed-version: Fixed from version 6.0rc3"
+
+# CVE-2024-0564 has no known resolution
+
+CVE_STATUS[CVE-2024-0565] = "cpe-stable-backport: Backported in 6.6.8"
+
+CVE_STATUS[CVE-2024-0582] = "cpe-stable-backport: Backported in 6.6.5"
+
+CVE_STATUS[CVE-2024-0584] = "cpe-stable-backport: Backported in 6.6.5"
+
+CVE_STATUS[CVE-2024-0607] = "cpe-stable-backport: Backported in 6.6.3"
+
+CVE_STATUS[CVE-2024-0639] = "fixed-version: Fixed from version 6.5rc1"
+
+CVE_STATUS[CVE-2024-0641] = "fixed-version: Fixed from version 6.6rc5"
+
+CVE_STATUS[CVE-2024-0646] = "cpe-stable-backport: Backported in 6.6.7"
+
+CVE_STATUS[CVE-2024-0775] = "fixed-version: Fixed from version 6.4rc2"
+
+# CVE-2024-0841 has no known resolution
+
+CVE_STATUS[CVE-2024-1085] = "cpe-stable-backport: Backported in 6.6.14"
+
+CVE_STATUS[CVE-2024-1086] = "cpe-stable-backport: Backported in 6.6.15"
+
+# CVE-2024-21803 has no known resolution
+
+# CVE-2024-22099 has no known resolution
+
+CVE_STATUS[CVE-2024-22705] = "cpe-stable-backport: Backported in 6.6.10"
+
+# CVE-2024-23307 has no known resolution
+
+# CVE-2024-23848 has no known resolution
+
+# CVE-2024-23849 has no known resolution
+
+# CVE-2024-23850 has no known resolution
+
+# CVE-2024-23851 has no known resolution