From: Thomas Petazzoni via buildroot <buildroot@buildroot.org>
To: "Clément Ramirez" <ramirez.clement3@gmail.com>
Cc: Romain Naour <romain.naour@gmail.com>, buildroot@buildroot.org
Subject: Re: [Buildroot] [PATCH] package/qemu: security bump version to 8.1.1
Date: Wed, 1 Nov 2023 17:29:35 +0100 [thread overview]
Message-ID: <20231101172935.4daa4d99@windsurf> (raw)
In-Reply-To: <CADRKr2oNM2btAby66VOSNCs2bJkheButc7R+5N7kB-Kc7YuWtg@mail.gmail.com>
Hello Clément,
Always happy to see some patches from you on Buildroot! :-)
On Tue, 10 Oct 2023 11:15:13 +0200
Clément Ramirez <ramirez.clement3@gmail.com> wrote:
> I will try to find a way to add an entry in the CPE database, and add a
> comment to explain why we are ignoring these CVEs.
In the end, did you send an e-mail to the NVD maintainers about this?
You actually don't need to look for how to add an entry in the CPE
database. Just drop an e-mail to the NVD maintainers, giving for each
CVE some clear evidence that there were fixed in 8.1.1, and ask them to
update the CVE entries. They will automatically take care of adding the
CPE entry, and update the CVE information.
Let me know if you want some help to achieve this.
Thanks!
Thomas
--
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot
next prev parent reply other threads:[~2023-11-01 16:29 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-10-10 7:05 [Buildroot] [PATCH] package/qemu: security bump version to 8.1.1 Clement Ramirez
2023-10-10 7:47 ` Baruch Siach via buildroot
2023-10-10 8:41 ` Clément Ramirez
2023-10-10 8:54 ` Baruch Siach via buildroot
2023-10-10 9:15 ` Clément Ramirez
2023-11-01 16:29 ` Thomas Petazzoni via buildroot [this message]
2023-11-02 9:37 ` Clément Ramirez
2023-11-02 9:47 ` Thomas Petazzoni via buildroot
2023-11-02 9:51 ` Clément Ramirez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20231101172935.4daa4d99@windsurf \
--to=buildroot@buildroot.org \
--cc=ramirez.clement3@gmail.com \
--cc=romain.naour@gmail.com \
--cc=thomas.petazzoni@bootlin.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox