All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Yoann Congal" <yoann.congal@smile.fr>
To: "Yoann Congal" <yoann.congal@smile.fr>,
	<openembedded-core@lists.openembedded.org>
Subject: Re: [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007
Date: Wed, 09 Sep 2026 19:00:23 +0200	[thread overview]
Message-ID: <DLAY2X2SD4KP.1P28H8QUJJ1P8@smile.fr> (raw)
In-Reply-To: <3d02f9f0f0ac74275633f2f9eff9c568e351457d.1788938909.git.yoann.congal@smile.fr>

On Wed Sep 9, 2026 at 9:29 AM CEST, Yoann Congal wrote:
> From: Hetvi Thakar <hthakar@cisco.com>
>
> Analysis:
> - NVD identifies the vulnerable code as net/tcp.c when
>   CONFIG_PROT_TCP is enabled [1].
> - tools-only_defconfig disables networking, so this code is not built
>   into u-boot-tools [2].
> - Hence ignoring the CVE for this recipe.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2026-29007
> [2] https://github.com/u-boot/u-boot/blob/v2026.01/configs/tools-only_defconfig
>
> Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
> Signed-off-by: Yoann Congal <yoann.congal@smile.fr>
> ---
>  meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> index 7eaf721ca83..0e57bb88849 100644
> --- a/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> +++ b/meta/recipes-bsp/u-boot/u-boot-tools_2026.01.bb
> @@ -1,2 +1,4 @@
>  require u-boot-common.inc
>  require u-boot-tools.inc
> +
> +CVE_STATUS[CVE-2026-29007] = "not-applicable-config: tools-only_defconfig disables networking; net/tcp.c is not compiled into u-boot-tools."

Hello,

I just noticed that these CVEs are not visible from our tracking because
the CPE is "u-boot" vs the PN "u-boot-tools".

To fix this, I plan to add to this series the recent patch:
[wrynose][PATCH] u-boot: share CVE_PRODUCT with u-boot-tools - Hiago De Franco
https://lore.kernel.org/all/20260909-uboot-cve-product-wrynose-v1-1-072b994b426f@baylibre.com/

Regards,
-- 
Yoann Congal
Smile ECS



  reply	other threads:[~2026-09-09 17:00 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  7:28 [OE-core][wrynose 00/38] Patch review Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 01/38] linux-yocto/6.18: update to v6.18.41 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 02/38] linux-yocto/6.18: update to v6.18.43 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 03/38] linux-yocto/6.18: update to v6.18.44 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 04/38] linux-yocto/6.18: update to v6.18.48 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 05/38] testimage: handle bootlog variants on failed qemu tests Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 06/38] openssl: upgrade 3.5.7 -> 3.5.8 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 07/38] apr-util: upgrade 1.6.3 -> 1.6.5 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 08/38] python3-pip: Fix CVE-2026-13346 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 09/38] time64: enable 64-bit time/file-offset flags for 32-bit nativesdk Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 10/38] grub: disable grub-protect for native builds Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 11/38] procps: ptest: skip flaky pgrep full process name match test Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 12/38] vim: Fix for CVE-2026-73072 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 13/38] vim: Fix for CVE-2026-73073 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 14/38] vim: Fix for CVE-2026-73074 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 15/38] vim: Fix for CVE-2026-73076 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 16/38] vim: Fix for CVE-2026-73077 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 17/38] vim: Fix for CVE-2026-73078 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 18/38] improve_kernel_cve_report: fix backported-patch check Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 19/38] p11-kit: upgrade 0.26.4 -> 0.26.5 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 20/38] python3-lxml: fix CVE-2026-41066 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 21/38] glibc: fix CVE-2026-19542 Yoann Congal
2026-09-10  4:42   ` Hemanth Kumar M D
2026-09-10 12:53     ` Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 22/38] libxfont: Fix CVE-2026-56001 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 23/38] libxfont: Fix CVE-2026-56002 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 24/38] libxfont: Fix CVE-2026-56003 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 25/38] wget: fix CVE-2026-16599 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 26/38] libarchive: mark CVE-2026-14164 as fixed-version Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 27/38] u-boot-tools: Ignore CVE-2026-29007 Yoann Congal
2026-09-09 17:00   ` Yoann Congal [this message]
2026-09-09  7:29 ` [OE-core][wrynose 28/38] u-boot-tools: Ignore CVE-2026-29008 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 29/38] u-boot-tools: Ignore CVE-2026-29009 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 30/38] u-boot, u-boot-tools: Correct CVE-2026-46728 attribution for FIT fix Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 31/38] wpa-supplicant: patch CVE-2026-58374 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 32/38] curl: patch CVE-2026-11352 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 33/38] curl: patch CVE-2026-11586 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 34/38] gnutls: fix CVE-2026-33845 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 35/38] perl: Fix CVE-2026-57433 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 36/38] wget: Fix CVE-2026-58470 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 37/38] python3-pip: Fix CVE-2026-8643 Yoann Congal
2026-09-09  7:29 ` [OE-core][wrynose 38/38] gawk: skip randtest in ptest suite Yoann Congal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLAY2X2SD4KP.1P28H8QUJJ1P8@smile.fr \
    --to=yoann.congal@smile.fr \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.