On Mon, 2026-08-03 at 01:48 -0700, Junjie Cao wrote:
> This is v2 of the triage of the CVEs from Paul Barker's "linux-yocto CVEs
> in need of triage" request [1], reworked according to his review [2]:
> one patch per CVE, primary sources cited in every commit message, and
> the three CVEs which have no upstream fix recorded as "unpatched" rather
> than left out.

Hi Junjie,

We briefly discussed this patch series on the review call today. We're
concerned about taking CVE status changes based on AI-Generated analysis
from a new contributor, when there are multiple ways to interpret the
various discussions online about these issues and it's not immediately
clear what the "right" answer is. So we need to give these patches a
thorough review. As we often point out in the weekly status emails, we
have limited bandwidth to do this sort of in-depth review, so we may not
be able to handle these patches quickly.

Some quick thoughts below:

> Summary of the ten verdicts:
> 
>   fixed-version     CVE-2022-1247   v6.17, rose_neigh refcount conversion

rose_connect() is now gone from mainline, so we can easily say this was
fixed with the removal of net/rose. Pointing at an earlier fix requires
more detailed review.

>                     CVE-2023-4010   v6.18, imon URB resubmit loop

This sounds like we're trying to infer the reporter's intent based on
'imon' being visible in a screenshot. We shouldn't be making guesses
just because the initial report quality is poor.

>   disputed          CVE-2022-0400   never substantiated, closed by three 
> vendors

This is probably right, but needs another look.

>   upstream-wontfix  CVE-2019-14899  weak host model, config-only mitigation

We shouldn't use upstream-wontfix unless that is an actual upstream
opinion. Ubuntu/RedHat are not upstream for the Linux kernel.

>                     CVE-2021-3714   inherent to KSM deduplication

As above.

>                     CVE-2021-3864   two fix attempts, neither merged

As above. Was the fix actually rejected by upstream or did it just go quiet?

>                     CVE-2022-4543   KASLR not a boundary against local 
> attackers

Sounds like there was some discussion with the kernel security team but
probably not a clear wontfix decision.

>   unpatched         CVE-2023-3397   JFS txEnd UAF, proposed fix withdrawn

Unclear if there is still a real problem here in mainline.

>                     CVE-2023-6238   NVMe fix applied then reverted

Probably correct but not completely sure.

>                     CVE-2023-6240   RSA timing oracle, fixed only in RHEL

Also probably correct but not completely sure. The commit message has
artifacts of the LLM being confused (Marvell/s390/unrelated commit
reference), those can be dropped.

Best regards,

-- 
Paul Barker

Attachment: signature.asc
Description: This is a digitally signed message part

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#242935): 
https://lists.openembedded.org/g/openembedded-core/message/242935
Mute This Topic: https://lists.openembedded.org/mt/120574077/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to