On Thu, 2026-07-23 at 12:15 +0000, Navuduri, Venkata Adhitya via
lists.openembedded.org wrote:
> Hello,
> 
> Regarding CVE-2023-3640 (x86 cpu_entry_area KASLR bypass, CVSS 7.8):
> The mainline fix is commit 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry 
> area") by Peter Zijlstra, merged in v6.2-rc1 
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=97e3d26b5e5f
> 
> 
> So, for Yocto releases shipping kernel >=6.2 version this fix is already 
> present. This fix needs back porting to kernel <6.2
> 
> For now, I can prepare a patch to add this CVE in the cve-exclusion.inc to 
> stop the CVE tool from reporting on this.
> 

Hi Adhitya,

Please send a patch to update cve-exclusion.inc, in the commit message
please include any information or references you have to to identify
commit 97e3d26b5e5f as the fix.

Best regards,

-- 
Paul Barker

Attachment: signature.asc
Description: This is a digitally signed message part

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#241937): 
https://lists.openembedded.org/g/openembedded-core/message/241937
Mute This Topic: https://lists.openembedded.org/mt/120395056/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to