[OE-core] [dunfell] [PATCH] binutils: Mark CVE-2022-47696 as patched

2023-11-30 Thread poojitha adireddy via lists.openembedded.org
CVE-2022-47696 and CVE-2023-25588 are representing similar kind of vulnerability. Reference: https://ubuntu.com/security/CVE-2022-47696 https://sourceware.org/bugzilla/show_bug.cgi?id=29677 Signed-off-by: poojitha adireddy --- meta/recipes-devtools/binutils/binutils/CVE-2023-25588.patch | 3 +++

[OE-core] [dunfell] [PATCH] binutils 2.34: Fix CVE-2021-46174

2023-11-28 Thread poojitha adireddy via lists.openembedded.org
Upstream Repository: https://sourceware.org/git/binutils-gdb.git Bug Details: https://nvd.nist.gov/vuln/detail/CVE-2021-46174 Type: Security Fix CVE: CVE-2021-46174 Score: 7.5 Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cad4d6b91e97 Signed-off-by: poojitha adireddy --- ...

[OE-core] [dunfell] [PATCH] qemu: Whitelist CVE

2023-11-13 Thread poojitha adireddy via lists.openembedded.org
Reason: CVE-2021-3947, issue introduced in v6.0.0-rc0 Reference: https://security-tracker.debian.org/tracker/CVE-2021-3947 Dunfell utilizes qemu v4.2.0, Hence whitelisting the CVE. Signed-off-by: poojitha adireddy --- meta/recipes-devtools/qemu/qemu.inc | 3 +++ 1 file changed, 3 insertions(+)