All of lore.kernel.org
 help / color / mirror / Atom feed
* [OE-core] [scarthgap] [PATCH] apt: CVE-2011-3374
@ 2026-06-01 13:40 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
  2026-06-09 11:28 ` Jeremy Rosen
  0 siblings, 1 reply; 3+ messages in thread
From: Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-06-01 13:40 UTC (permalink / raw)
  To: openembedded-core; +Cc: xe-linux-external, to, Anil Dongare

From: Anil Dongare <adongare@cisco.com>

Details: https://security-tracker.debian.org/tracker/CVE-2011-3374

The vulnerability is a design-level flaw in the legacy apt-key utility regarding
the global trust model of GPG keys.

This is marked as not-applicable-config because apt-key net-update is
disabled by default, and Debian vendor configuration does not define the
archive keyring URI required to use that path. Ignore this CVE in this
recipe due to this configuration.

Signed-off-by: Anil Dongare <adongare@cisco.com>
---
 meta/recipes-devtools/apt/apt_2.6.1.bb | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/meta/recipes-devtools/apt/apt_2.6.1.bb b/meta/recipes-devtools/apt/apt_2.6.1.bb
index 12915660b0..8b48de3498 100644
--- a/meta/recipes-devtools/apt/apt_2.6.1.bb
+++ b/meta/recipes-devtools/apt/apt_2.6.1.bb
@@ -38,6 +38,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/"
 # to express 'divisible by 4 plus 2' in regex (that I know of), let's hardcode a few.
 UPSTREAM_CHECK_REGEX = "[^\d\.](?P<pver>((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar"
 
+# Not applicable: Debian vendor configuration does not enable apt-key net-update.
+CVE_STATUS[CVE-2011-3374] = "not-applicable-config: apt-key net-update is disabled by default and Debian vendor configuration has no archive keyring URI"
+
 inherit cmake perlnative bash-completion useradd
 
 # User is added to allow apt to drop privs, will runtime warn without
-- 
2.44.4



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [OE-core] [scarthgap] [PATCH] apt: CVE-2011-3374
  2026-06-01 13:40 [OE-core] [scarthgap] [PATCH] apt: CVE-2011-3374 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
@ 2026-06-09 11:28 ` Jeremy Rosen
  2026-08-25 11:17   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 1 reply; 3+ messages in thread
From: Jeremy Rosen @ 2026-06-09 11:28 UTC (permalink / raw)
  To: adongare, openembedded-core; +Cc: xe-linux-external, to

Hello Anil

It seems this CVE is not fixed upstream, so the not-applicable tag must
also be applied to master and wrynose

please submit patches for those two branches and then ping here

thanks a lot
Jeremy

On Mon Jun 1, 2026 at 3:40 PM CEST, Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Anil Dongare <adongare@cisco.com>
>
> Details: https://security-tracker.debian.org/tracker/CVE-2011-3374
>
> The vulnerability is a design-level flaw in the legacy apt-key utility regarding
> the global trust model of GPG keys.
>
> This is marked as not-applicable-config because apt-key net-update is
> disabled by default, and Debian vendor configuration does not define the
> archive keyring URI required to use that path. Ignore this CVE in this
> recipe due to this configuration.
>
> Signed-off-by: Anil Dongare <adongare@cisco.com>
> ---
>  meta/recipes-devtools/apt/apt_2.6.1.bb | 3 +++
>  1 file changed, 3 insertions(+)
>
> diff --git a/meta/recipes-devtools/apt/apt_2.6.1.bb b/meta/recipes-devtools/apt/apt_2.6.1.bb
> index 12915660b0..8b48de3498 100644
> --- a/meta/recipes-devtools/apt/apt_2.6.1.bb
> +++ b/meta/recipes-devtools/apt/apt_2.6.1.bb
> @@ -38,6 +38,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/"
>  # to express 'divisible by 4 plus 2' in regex (that I know of), let's hardcode a few.
>  UPSTREAM_CHECK_REGEX = "[^\d\.](?P<pver>((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar"
>  
> +# Not applicable: Debian vendor configuration does not enable apt-key net-update.
> +CVE_STATUS[CVE-2011-3374] = "not-applicable-config: apt-key net-update is disabled by default and Debian vendor configuration has no archive keyring URI"
> +
>  inherit cmake perlnative bash-completion useradd
>  
>  # User is added to allow apt to drop privs, will runtime warn without



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [scarthgap] [PATCH] apt: CVE-2011-3374
  2026-06-09 11:28 ` Jeremy Rosen
@ 2026-08-25 11:17   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
  0 siblings, 0 replies; 3+ messages in thread
From: Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) @ 2026-08-25 11:17 UTC (permalink / raw)
  To: openembedded-core

[-- Attachment #1: Type: text/plain, Size: 2777 bytes --]

On Tue, Jun 9, 2026 at 04:58 PM, Jérémy Rosen wrote:

> 
> Hello Anil
> 
> It seems this CVE is not fixed upstream, so the not-applicable tag must
> also be applied to master and wrynose
> 
> please submit patches for those two branches and then ping here
> 
> thanks a lot
> Jeremy
> 
> On Mon Jun 1, 2026 at 3:40 PM CEST, Anil Dongare -X (adongare - E
> INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> 
>> From: Anil Dongare <adongare@cisco.com>
>> 
>> Details: https://security-tracker.debian.org/tracker/CVE-2011-3374
>> 
>> The vulnerability is a design-level flaw in the legacy apt-key utility
>> regarding
>> the global trust model of GPG keys.
>> 
>> This is marked as not-applicable-config because apt-key net-update is
>> disabled by default, and Debian vendor configuration does not define the
>> archive keyring URI required to use that path. Ignore this CVE in this
>> recipe due to this configuration.
>> 
>> Signed-off-by: Anil Dongare <adongare@cisco.com>
>> ---
>> meta/recipes-devtools/apt/apt_2.6.1.bb | 3 +++
>> 1 file changed, 3 insertions(+)
>> 
>> diff --git a/meta/recipes-devtools/apt/apt_2.6.1.bb
>> b/meta/recipes-devtools/apt/apt_2.6.1.bb
>> index 12915660b0..8b48de3498 100644
>> --- a/meta/recipes-devtools/apt/apt_2.6.1.bb
>> +++ b/meta/recipes-devtools/apt/apt_2.6.1.bb
>> @@ -38,6 +38,9 @@ UPSTREAM_CHECK_URI = "${DEBIAN_MIRROR}/main/a/apt/"
>> # to express 'divisible by 4 plus 2' in regex (that I know of), let's
>> hardcode a few.
>> UPSTREAM_CHECK_REGEX =
>> "[^\d\.](?P<pver>((2\.2)|(2\.6)|(3\.0)|(3\.4)|(3\.8)|(4\.2))(\.\d+)+)\.tar"
>> 
>> 
>> +# Not applicable: Debian vendor configuration does not enable apt-key
>> net-update.
>> +CVE_STATUS[CVE-2011-3374] = "not-applicable-config: apt-key net-update is
>> disabled by default and Debian vendor configuration has no archive keyring
>> URI"
>> +
>> inherit cmake perlnative bash-completion useradd
>> 
>> # User is added to allow apt to drop privs, will runtime warn without
> 
> 

Hi Jeremy,

As requested, patches for the same CVE were submitted for both
master and wrynose.

The patch for master has now been merged, and the corresponding
wrynose patch has also been submitted upstream.

Master:
https://git.openembedded.org/openembedded-core/commit/?id=5126e4792ddd8e6c721c47733d287633c234f2a9 ( https://git.openembedded.org/openembedded-core/commit/?id=5126e4792ddd8e6c721c47733d287633c234f2a9 )

Wrynose:
https://patchwork.yoctoproject.org/project/oe-core/patch/20260825110148.2163688-1-hthakar@cisco.com/ ( https://patchwork.yoctoproject.org/project/oe-core/patch/20260825110148.2163688-1-hthakar@cisco.com/ )

Could you please review the Scarthgap patch now?

Regards,
Hetvi

[-- Attachment #2: Type: text/html, Size: 3366 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-25 11:17 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-01 13:40 [OE-core] [scarthgap] [PATCH] apt: CVE-2011-3374 Anil Dongare -X (adongare - E INFOCHIPS PRIVATE LIMITED at Cisco)
2026-06-09 11:28 ` Jeremy Rosen
2026-08-25 11:17   ` Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.