From: Richard Purdie <richard.purdie@linuxfoundation.org>
To: Quentin Schulz <quentin.schulz@theobroma-systems.com>
Cc: openembedded-core@lists.openembedded.org, anuj.mittal@intel.com,
Alexander Kanavin <alex.kanavin@gmail.com>
Subject: Re: [OE-core] [honister][PATCH 2/2] util-linux: upgrade 2.37.3 -> 2.37.4
Date: Mon, 07 Mar 2022 11:44:45 +0000 [thread overview]
Message-ID: <cdbe8623d35c2ebf943806de4fd4400a8636f4f0.camel@linuxfoundation.org> (raw)
In-Reply-To: <62fd97c4-b5e5-42d5-cc13-ae0883184210@theobroma-systems.com>
On Mon, 2022-03-07 at 12:26 +0100, Quentin Schulz wrote:
> Hi all,
>
> On 3/7/22 12:21, Quentin Schulz wrote:
> > From: Alexander Kanavin <alex.kanavin@gmail.com>
> >
> > Signed-off-by: Alexander Kanavin <alex.kanavin@gmail.com>
> > Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
> > (cherry picked from commit 6a3289c4786c4d278e2bf0ec1a5e04363772d8bc)
> > Signed-off-by: Quentin Schulz <quentin.schulz@theobroma-systems.com>
> > ---
>
> https://www.spinics.net/lists/util-linux-ng/msg17037.html 2.37.3 fixes
> two CVEs (not listed on nvdist database for some reason).
>
> https://www.spinics.net/lists/util-linux-ng/msg17087.html 2.37.4 fixes
> one CVE (not listed on bvdist for some reason).
>
> I think it might be useful for release maintainer(s) if we mention in
> the commit log or commit title if it's a security bump or not when
> sending patches for version bumps to master? What do you think? (FYI,
> Buildroot seems to do it regularly and it helps me with keeping my
> vendor tree somewhat up-to-date security wise).
I'm happy if people do mention it (I did for expat recently) but I'm not going
to block upgrades on the information being missing (how would I tell?).
We're struggling to get people to submit upgrades so I'm reluctant to make it
harder for them.
Cheers,
Richard
next prev parent reply other threads:[~2022-03-07 11:44 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-03-07 11:21 [honister][PATCH 1/2] util-linux: update 2.37.2 -> 2.37.3 Quentin Schulz
2022-03-07 11:21 ` [honister][PATCH 2/2] util-linux: upgrade 2.37.3 -> 2.37.4 Quentin Schulz
2022-03-07 11:26 ` [OE-core] " Quentin Schulz
2022-03-07 11:44 ` Richard Purdie [this message]
2022-03-07 11:51 ` Quentin Schulz
2022-03-07 11:53 ` Richard Purdie
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cdbe8623d35c2ebf943806de4fd4400a8636f4f0.camel@linuxfoundation.org \
--to=richard.purdie@linuxfoundation.org \
--cc=alex.kanavin@gmail.com \
--cc=anuj.mittal@intel.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=quentin.schulz@theobroma-systems.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.