* [kirkstone][dunfell] CVE-2023-25193 fix request
@ 2023-03-10 7:29 DC
2023-03-10 8:20 ` [OE-core] " Polampalli, Archana
0 siblings, 1 reply; 4+ messages in thread
From: DC @ 2023-03-10 7:29 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 489 bytes --]
Hi Team,
We are working on CVE-2023-25193 for kirkstone and dunfell branch as it is causing errors in our applications.
There have been previous threads pointing to the issues that backporting is difficult due to code changes and new files being added and there are no second thoughts for the same.
Could you please suggest how can we proceed to fix it ? Version updates is out of scope due to various internal reasons. If anyone can help, it would be great help.
Thanks,
DC
[-- Attachment #2: Type: text/html, Size: 547 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [OE-core] [kirkstone][dunfell] CVE-2023-25193 fix request
2023-03-10 7:29 [kirkstone][dunfell] CVE-2023-25193 fix request DC
@ 2023-03-10 8:20 ` Polampalli, Archana
2023-03-10 8:32 ` Siddharth
0 siblings, 1 reply; 4+ messages in thread
From: Polampalli, Archana @ 2023-03-10 8:20 UTC (permalink / raw)
To: openembedded-core@lists.openembedded.org, davidcorbe@outlook.com
[-- Attachment #1: Type: text/plain, Size: 1211 bytes --]
Hi,
One of my team member has worked on it and she will submit patch to upstream kirkstone in one or two days.
Regards,
Archana
________________________________
From: openembedded-core@lists.openembedded.org <openembedded-core@lists.openembedded.org> on behalf of DC via lists.openembedded.org <davidcorbe=outlook.com@lists.openembedded.org>
Sent: Friday, March 10, 2023 12:59 PM
To: openembedded-core@lists.openembedded.org <openembedded-core@lists.openembedded.org>
Subject: [OE-core] [kirkstone][dunfell] CVE-2023-25193 fix request
CAUTION: This email comes from a non Wind River email account!
Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hi Team,
We are working on CVE-2023-25193 for kirkstone and dunfell branch as it is causing errors in our applications.
There have been previous threads pointing to the issues that backporting is difficult due to code changes and new files being added and there are no second thoughts for the same.
Could you please suggest how can we proceed to fix it ? Version updates is out of scope due to various internal reasons. If anyone can help, it would be great help.
Thanks,
DC
[-- Attachment #2: Type: text/html, Size: 3012 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [kirkstone][dunfell] CVE-2023-25193 fix request
2023-03-10 8:20 ` [OE-core] " Polampalli, Archana
@ 2023-03-10 8:32 ` Siddharth
2023-03-23 5:12 ` DC
0 siblings, 1 reply; 4+ messages in thread
From: Siddharth @ 2023-03-10 8:32 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 292 bytes --]
The Backport was a bit tricky but i feel its done.
I have submitted for kirkstone branch and the all the tests passed on my end.
Will be submitting it for dunfell soon too.
Let me know incase if the problem still persists. If it passes, i am happy to help :)
Regards,
Siddharth
[-- Attachment #2: Type: text/html, Size: 359 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [kirkstone][dunfell] CVE-2023-25193 fix request
2023-03-10 8:32 ` Siddharth
@ 2023-03-23 5:12 ` DC
0 siblings, 0 replies; 4+ messages in thread
From: DC @ 2023-03-23 5:12 UTC (permalink / raw)
To: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 291 bytes --]
Siddharth and Steve ,
a little late but thank-you for the patch.
we were in the process of rigorous testing and it has passed with submitted patches on all 3 branches and our applications are running smoothly even on corner cases which were vulnerable due to the CVE.
Regards,
DC
[-- Attachment #2: Type: text/html, Size: 320 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2023-03-23 5:12 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-03-10 7:29 [kirkstone][dunfell] CVE-2023-25193 fix request DC
2023-03-10 8:20 ` [OE-core] " Polampalli, Archana
2023-03-10 8:32 ` Siddharth
2023-03-23 5:12 ` DC
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox