Re: [OE-core] OE-core CVE metrics for master on Sun 12 Nov 2023 01:00:01 AM HST

2023-11-13 Thread Khem Raj
On Mon, Nov 13, 2023 at 5:55 AM Ross Burton wrote: > > On 12 Nov 2023, at 11:17, Steve Sakoman via lists.openembedded.org > wrote: > > New this week: 8 CVEs > > Such fun! > > I did some research and have included my notes below. Do we have any > volunteers for the avahi patchbomb? I think we

Re: [OE-core] OE-core CVE metrics for master on Sun 12 Nov 2023 01:00:01 AM HST

2023-11-13 Thread Ross Burton
On 12 Nov 2023, at 11:17, Steve Sakoman via lists.openembedded.org wrote: > New this week: 8 CVEs Such fun! I did some research and have included my notes below. Do we have any volunteers for the avahi patchbomb? > CVE-2023-3397 (CVSS3: 6.3 MEDIUM): linux-yocto > https://web.nvd.nist.gov/vi

[OE-core] OE-core CVE metrics for master on Sun 12 Nov 2023 01:00:01 AM HST

2023-11-12 Thread Steve Sakoman
Branch: master New this week: 8 CVEs CVE-2023-3397 (CVSS3: 6.3 MEDIUM): linux-yocto https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3397 * CVE-2023-38469 (CVSS3: 5.5 MEDIUM): avahi https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-38469 * CVE-2023-38470 (CVSS3: 5.5 MEDIUM): ava