CIP-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Urgent: Regarding Fixing of Security Vulnerabilities
@ 2026-07-09  4:53 whyshall
  2026-07-09  9:13 ` whyshall.dev
       [not found] ` <Groupsio.1.CAOksrezPuEAoJ86FHMS_ajoH0h7pe3usksyo84n5rF9RKHfu4g@mail.gmail.com>
  0 siblings, 2 replies; 6+ messages in thread
From: whyshall @ 2026-07-09  4:53 UTC (permalink / raw)
  To: cip-dev

[-- Attachment #1: Type: text/plain, Size: 1623 bytes --]

 Hi ,

We are planning to migrate our product to the Linux Kernel 4.19.y CIP
release to benefit from its long-term maintenance and security updates.

We have a few questions regarding security vulnerability tracking for the
CIP kernel:

   1. Is there any tool, dashboard, or documentation available to determine:
      - The Kernel CVEs applicable to a specific 4.19.y CIP release.
      - Which CVEs have already been fixed till the given CIP release.
      - Which CVEs are still outstanding.
      2. Is there a published roadmap or policy indicating how unresolved
   Kernel CVEs are evaluated and scheduled for backporting to the 4.19.y CIP
   branch?
   3. For CVEs that remain unfixed in the CIP kernel:
      - What are the expected implications or risks for users of the CIP
      release?
      - Are these vulnerabilities typically already addressed in the
      upstream mainline Linux kernel, with backporting to CIP pending due to
      compatibility or maintenance considerations?
      4. If there are unfixed vulnerabilities that are considered critical
   for our product, what is the recommended approach to address them?


   - Does the CIP project provide any guidance or best practices for
      evaluating, backporting, or mitigating such vulnerabilities?
      - If a required fix is available only in the upstream mainline
      kernel, are there any recommendations or guidelines for safely
backporting
      it to the CIP kernel?

Any guidance on the recommended process or tools for tracking the security
status of CIP kernel releases would be greatly appreciated.

Thank you for your support.

[-- Attachment #2: Type: text/html, Size: 2998 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-07-16 10:48 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-09  4:53 Urgent: Regarding Fixing of Security Vulnerabilities whyshall
2026-07-09  9:13 ` whyshall.dev
     [not found] ` <Groupsio.1.CAOksrezPuEAoJ86FHMS_ajoH0h7pe3usksyo84n5rF9RKHfu4g@mail.gmail.com>
2026-07-13 21:08   ` [cip-dev] " Pavel Machek
2026-07-14  5:10     ` whyshall
2026-07-14  7:48       ` whyshall
2026-07-16 10:48       ` whyshall

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox