All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-core@lists.openembedded.org
Subject: Re: [scarthgap] [PATCH] apt: CVE-2011-3374
Date: Tue, 25 Aug 2026 04:17:08 -0700	[thread overview]
Message-ID: <2283556.1787656628832856546@lists.openembedded.org> (raw)
In-Reply-To: <DJ4HENS1HI6E.CJ0J0A7TESHU@smile.fr>

[-- Attachment #1: Type: text/plain, Size: 2777 bytes --]

On Tue, Jun 9, 2026 at 04:58 PM, Jérémy Rosen wrote:

> 
> Hello Anil
> 
> It seems this CVE is not fixed upstream, so the not-applicable tag must
> also be applied to master and wrynose
> 
> please submit patches for those two branches and then ping here
> 
> thanks a lot
> Jeremy
> 
> On Mon Jun 1, 2026 at 3:40 PM CEST, Anil Dongare -X (adongare - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> 
>> From: Anil Dongare <adongare@cisco.com>
>> 
>> Details: https://security-tracker.debian.org/tracker/CVE-2011-3374
>> 
>> The vulnerability is a design-level flaw in the legacy apt-key utility
>> regarding
>> the global trust model of GPG keys.
>> 
>> This is marked as not-applicable-config because apt-key net-update is
>> disabled by default, and Debian vendor configuration does not define the
>> archive keyring URI required to use that path. Ignore this CVE in this
>> recipe due to this configuration.
>> 
>> Signed-off-by: Anil Dongare <adongare@cisco.com>
>> ---
>> meta/recipes-devtools/apt/apt_2.6.1.bb | 3 +++
>> 1 file changed, 3 insertions(+)
>> 
>> diff --git a/meta/recipes-devtools/apt/apt_2.6.1.bb
>> b/meta/recipes-devtools/apt/apt_2.6.1.bb
>> index 12915660b0..8b48de3498 100644
>> --- a/meta/recipes-devtools/apt/apt_2.6.1.bb
>> +++ b/meta/recipes-devtools/apt/apt_2.6.1.bb
>> @@ -38,6 +38,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/"
>> # to express 'divisible by 4 plus 2' in regex (that I know of), let's
>> hardcode a few.
>> UPSTREAM_CHECK_REGEX =
>> "[^\d\.](?P<pver>((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar"
>> 
>> 
>> +# Not applicable: Debian vendor configuration does not enable apt-key
>> net-update.
>> +CVE_STATUS[CVE-2011-3374] = "not-applicable-config: apt-key net-update is
>> disabled by default and Debian vendor configuration has no archive keyring
>> URI"
>> +
>> inherit cmake perlnative bash-completion useradd
>> 
>> # User is added to allow apt to drop privs, will runtime warn without
> 
> 

Hi Jeremy,

As requested, patches for the same CVE were submitted for both
master and wrynose.

The patch for master has now been merged, and the corresponding
wrynose patch has also been submitted upstream.

Master:
https://git.openembedded.org/openembedded-core/commit/?id=5126e4792ddd8e6c721c47733d287633c234f2a9 ( https://git.openembedded.org/openembedded-core/commit/?id=5126e4792ddd8e6c721c47733d287633c234f2a9 )

Wrynose:
https://patchwork.yoctoproject.org/project/oe-core/patch/20260825110148.2163688-1-hthakar@cisco.com/ ( https://patchwork.yoctoproject.org/project/oe-core/patch/20260825110148.2163688-1-hthakar@cisco.com/ )

Could you please review the Scarthgap patch now?

Regards,
Hetvi

[-- Attachment #2: Type: text/html, Size: 3366 bytes --]

      reply	other threads:[~2026-08-25 11:17 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-01 13:40 [OE-core] [scarthgap] [PATCH] apt: CVE-2011-3374 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-09 11:28 ` Jeremy Rosen
2026-08-25 11:17   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2283556.1787656628832856546@lists.openembedded.org \
    --to=hthakar@cisco.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.