All of lore.kernel.org
 help / color / mirror / Atom feed
* [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master
@ 2026-09-02 22:26 Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 1/4] arm/optee: modify CVE_PRODUCT Javier Tia
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Javier Tia @ 2026-09-02 22:26 UTC (permalink / raw)
  To: meta-arm; +Cc: Javier Tia

The four CVE_PRODUCT commits from 2026-06-10 never reached the release
branches, so cve-check on wrynose still scans these recipes under names
that match nothing in NVD. A recipe that matches nothing reports zero
CVEs, which is indistinguishable from a recipe that was scanned and found
clean.

All four apply cleanly here. The same series minus scp-firmware is sent
separately for scarthgap, where the shared scp-firmware.inc does not
exist.

Measured against the NVD 2.0 API, replaying each CPE version range through
oe.cve_check.Version at the PVs that ship:

  trustedfirmware:trusted_firmware-a   7 records, none reachable today
  arm:arm-trusted-firmware             0 records
  arm:arm_trusted_firmware             0 records

For trusted-firmware-a that turns a silent zero into a real scan: TF-A
2.10 gains one genuine unpatched finding (CVE-2023-31339), while 2.12 and
2.14 gain the scan and no finding.

Note this makes affected recipes start reporting CVEs where they reported
none, which will look like a regression to anyone gating CI on a count.
That is the intended effect rather than a side effect.

Cherry-picked from master with no changes; each patch carries its
(cherry picked from commit ...) line. Found while auditing CVE_PRODUCT
coverage on an i.MX BSP built from scarthgap.

Jon Mason (4):
  arm/optee: modify CVE_PRODUCT
  arm/trusted-firmware-a: modify CVE_PRODUCT
  arm/trusted-firmware-m: add CVE_PRODUCT
  arm/scp-firmware: add CVE_PRODUCT

 meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc            | 3 +++
 .../recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc     | 3 ++-
 .../recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc     | 2 ++
 meta-arm/recipes-security/optee/optee-os.inc                  | 4 +++-
 4 files changed, 10 insertions(+), 2 deletions(-)

-- 
Javier Tia



^ permalink raw reply	[flat|nested] 5+ messages in thread

* [wrynose PATCH 1/4] arm/optee: modify CVE_PRODUCT
  2026-09-02 22:26 [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master Javier Tia
@ 2026-09-02 22:26 ` Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 2/4] arm/trusted-firmware-a: " Javier Tia
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: Javier Tia @ 2026-09-02 22:26 UTC (permalink / raw)
  To: meta-arm; +Cc: Jon Mason, Javier Tia

From: Jon Mason <jon.mason@arm.com>

Per https://nvd.nist.gov/products/cpe/detail/EB42962B-24FD-4716-B3E2-69F3258A57CF
adding "trustedfirmware:op-tee"

We can probably remove "linaro:op-tee", since it has been depreciated.
Fearing unintended issues, leaving it in for now.

Signed-off-by: Jon Mason <jon.mason@arm.com>
(cherry picked from commit 81f5a92193d37027670f2c9b767ccbcd29d1e78c)
Signed-off-by: Javier Tia <javier@peridio.com>
---
 meta-arm/recipes-security/optee/optee-os.inc | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/meta-arm/recipes-security/optee/optee-os.inc b/meta-arm/recipes-security/optee/optee-os.inc
index 076e482b..95c41fb1 100644
--- a/meta-arm/recipes-security/optee/optee-os.inc
+++ b/meta-arm/recipes-security/optee/optee-os.inc
@@ -8,7 +8,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=c1f21c4f72f372ef38a5a4aee55ec173"
 inherit deploy python3native
 require optee.inc
 
-CVE_PRODUCT = "linaro:op-tee op-tee:op-tee_os"
+CVE_PRODUCT = "linaro:op-tee \
+               op-tee:op-tee_os \
+               trustedfirmware:op-tee"
 
 DEPENDS = "python3-pyelftools-native python3-cryptography-native"
 
-- 
Javier Tia



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [wrynose PATCH 2/4] arm/trusted-firmware-a: modify CVE_PRODUCT
  2026-09-02 22:26 [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 1/4] arm/optee: modify CVE_PRODUCT Javier Tia
@ 2026-09-02 22:26 ` Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 3/4] arm/trusted-firmware-m: add CVE_PRODUCT Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 4/4] arm/scp-firmware: " Javier Tia
  3 siblings, 0 replies; 5+ messages in thread
From: Javier Tia @ 2026-09-02 22:26 UTC (permalink / raw)
  To: meta-arm; +Cc: Jon Mason, Javier Tia

From: Jon Mason <jon.mason@arm.com>

Per https://nvd.nist.gov/products/cpe/detail/2E1BD3E8-DF65-42E3-A0BA-747137D6DEF2
Adding "trustedfirmware:trusted_firmware-a"

We can probably remove "arm:trusted_firmware-a", since it has been
depreciated.  Fearing unintended issues, leaving it in for now.

Signed-off-by: Jon Mason <jon.mason@arm.com>
(cherry picked from commit e2e63f20b504c31a4600f95764d3561c32b4b2f7)
Signed-off-by: Javier Tia <javier@peridio.com>
---
 meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc b/meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc
index 6a2c0da9..fc8779f9 100644
--- a/meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc
+++ b/meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a.inc
@@ -242,4 +242,5 @@ INSANE_SKIP:${PN}-dbg += "buildpaths"
 CVE_PRODUCT = "arm:arm-trusted-firmware \
                arm:trusted_firmware-a \
                arm:arm_trusted_firmware \
-               arm_trusted_firmware_project:arm_trusted_firmware"
+               arm_trusted_firmware_project:arm_trusted_firmware \
+               trustedfirmware:trusted_firmware-a"
-- 
Javier Tia



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [wrynose PATCH 3/4] arm/trusted-firmware-m: add CVE_PRODUCT
  2026-09-02 22:26 [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 1/4] arm/optee: modify CVE_PRODUCT Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 2/4] arm/trusted-firmware-a: " Javier Tia
@ 2026-09-02 22:26 ` Javier Tia
  2026-09-02 22:26 ` [wrynose PATCH 4/4] arm/scp-firmware: " Javier Tia
  3 siblings, 0 replies; 5+ messages in thread
From: Javier Tia @ 2026-09-02 22:26 UTC (permalink / raw)
  To: meta-arm; +Cc: Jon Mason, Javier Tia

From: Jon Mason <jon.mason@arm.com>

Per https://nvd.nist.gov/products/cpe/detail/C0F7CF14-9ACD-42C5-A1F8-839937F8C4DC
add CVE_PRODUCT entry.  Since there wasn't one existing, there is no
need to remove anything.

Signed-off-by: Jon Mason <jon.mason@arm.com>
(cherry picked from commit d0b93e582c7beb57e2d446311a93f5ab8b94fce1)
Signed-off-by: Javier Tia <javier@peridio.com>
---
 meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc b/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc
index 4e3c5912..86085757 100644
--- a/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc
+++ b/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m.inc
@@ -118,3 +118,5 @@ INSANE_SKIP:${PN}-dbg += "buildpaths"
 # Target binaries will be 32-bit Arm
 INSANE_SKIP:${PN} += "arch"
 INSANE_SKIP:${PN}-dbg += "arch"
+
+CVE_PRODUCT = "trustedfirmware:trusted_firmware-m"
-- 
Javier Tia



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [wrynose PATCH 4/4] arm/scp-firmware: add CVE_PRODUCT
  2026-09-02 22:26 [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master Javier Tia
                   ` (2 preceding siblings ...)
  2026-09-02 22:26 ` [wrynose PATCH 3/4] arm/trusted-firmware-m: add CVE_PRODUCT Javier Tia
@ 2026-09-02 22:26 ` Javier Tia
  3 siblings, 0 replies; 5+ messages in thread
From: Javier Tia @ 2026-09-02 22:26 UTC (permalink / raw)
  To: meta-arm; +Cc: Jon Mason, Javier Tia

From: Jon Mason <jon.mason@arm.com>

Per https://nvd.nist.gov/products/cpe/detail/593B1385-F4BE-452B-AE3B-51627F6CAE45
add CVE_PRODUCT entry.  Since there wasn't one existing, there is no
need to remove anything.

Signed-off-by: Jon Mason <jon.mason@arm.com>
(cherry picked from commit 9aaee17adb6cb6c92f360c18a0331a4cab4327a4)
Signed-off-by: Javier Tia <javier@peridio.com>
---
 meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc b/meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc
index 4623afe8..032445b3 100644
--- a/meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc
+++ b/meta-arm/recipes-bsp/scp-firmware/scp-firmware.inc
@@ -96,3 +96,6 @@ do_install() {
 INSANE_SKIP:${PN}-dbg += "arch"
 INHIBIT_PACKAGE_DEBUG_SPLIT = "1"
 INHIBIT_PACKAGE_STRIP = "1"
+
+CVE_PRODUCT = "arm:scp-firmware \
+               arm:scp_firmware"
-- 
Javier Tia



^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-02 22:26 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 22:26 [wrynose PATCH 0/4] backport the CVE_PRODUCT fixes from master Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 1/4] arm/optee: modify CVE_PRODUCT Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 2/4] arm/trusted-firmware-a: " Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 3/4] arm/trusted-firmware-m: add CVE_PRODUCT Javier Tia
2026-09-02 22:26 ` [wrynose PATCH 4/4] arm/scp-firmware: " Javier Tia

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.