On Thu, 2026-07-23 at 12:15 +0000, Navuduri, Venkata Adhitya via
lists.openembedded.org wrote:
> Hello,
>
> Regarding CVE-2023-3640 (x86 cpu_entry_area KASLR bypass, CVSS 7.8):
> The mainline fix is commit 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry
> area") by Peter Zijlstra, merged in v6.2-rc1
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=97e3d26b5e5f
>
>
> So, for Yocto releases shipping kernel >=6.2 version this fix is already
> present. This fix needs back porting to kernel <6.2
>
> For now, I can prepare a patch to add this CVE in the cve-exclusion.inc to
> stop the CVE tool from reporting on this.
> Hi Adhitya, Please send a patch to update cve-exclusion.inc, in the commit message please include any information or references you have to to identify commit 97e3d26b5e5f as the fix. Best regards, -- Paul Barker
signature.asc
Description: This is a digitally signed message part
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#241937): https://lists.openembedded.org/g/openembedded-core/message/241937 Mute This Topic: https://lists.openembedded.org/mt/120395056/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
