From: Javier Tia <javier@peridio.com>
To: meta-arm@lists.yoctoproject.org
Cc: Javier Tia <javier@peridio.com>
Subject: [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master
Date: Wed, 2 Sep 2026 16:26:42 -0600 [thread overview]
Message-ID: <20260902222646.2945592-1-javier@peridio.com> (raw)
The four CVE_PRODUCT commits from 2026-06-10 never reached the release
branches, so cve-check on wrynose still scans these recipes under names
that match nothing in NVD. A recipe that matches nothing reports zero
CVEs, which is indistinguishable from a recipe that was scanned and found
clean.
All four apply cleanly here. The same series minus scp-firmware is sent
separately for scarthgap, where the shared scp-firmware.inc does not
exist.
Measured against the NVD 2.0 API, replaying each CPE version range through
oe.cve_check.Version at the PVs that ship:
trustedfirmware:trusted_firmware-a 7 records, none reachable today
arm:arm-trusted-firmware 0 records
arm:arm_trusted_firmware 0 records
For trusted-firmware-a that turns a silent zero into a real scan: TF-A
2.10 gains one genuine unpatched finding (CVE-2023-31339), while 2.12 and
2.14 gain the scan and no finding.
Note this makes affected recipes start reporting CVEs where they reported
none, which will look like a regression to anyone gating CI on a count.
That is the intended effect rather than a side effect.
Cherry-picked from master with no changes; each patch carries its
(cherry picked from commit ...) line. Found while auditing CVE_PRODUCT
coverage on an i.MX BSP built from scarthgap.
Jon Mason (4):
arm/optee: modify CVE_PRODUCT
arm/trusted-firmware-a: modify CVE_PRODUCT
arm/trusted-firmware-m: add CVE_PRODUCT
arm/scp-firmware: add CVE_PRODUCT
meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc | 3 +++
.../recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc | 3 ++-
.../recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc | 2 ++
meta-arm/recipes-security/optee/optee-os.inc | 4 +++-
4 files changed, 10 insertions(+), 2 deletions(-)
--
Javier Tia
next reply other threads:[~2026-09-02 22:26 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 22:26 Javier Tia [this message]
2026-09-02 22:26 ` [wrynose PATCH 1/4] arm/optee: modify CVE_PRODUCT Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 2/4] arm/trusted-firmware-a: " Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 3/4] arm/trusted-firmware-m: add CVE_PRODUCT Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 4/4] arm/scp-firmware: " Javier Tia
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902222646.2945592-1-javier@peridio.com \
--to=javier@peridio.com \
--cc=meta-arm@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.