From: ankur.tyagi85@gmail.com
To: openembedded-devel@lists.openembedded.org
Cc: Shinji Matsunaga <shin.matsunaga@fujitsu.com>,
Khem Raj <raj.khem@gmail.com>,
Ankur Tyagi <ankur.tyagi85@gmail.com>
Subject: [oe][meta-oe][scarthgap][PATCH 20/38] audit: Fix CVE_PRODUCT
Date: Thu, 13 Nov 2025 19:18:55 +1300 [thread overview]
Message-ID: <20251113061914.3756301-20-ankur.tyagi85@gmail.com> (raw)
In-Reply-To: <20251113061914.3756301-1-ankur.tyagi85@gmail.com>
From: Shinji Matsunaga <shin.matsunaga@fujitsu.com>
Fix "audit" set in CVE_PRODUCT to "linux:audit" to detect only vulnerabilities where the vendor is "linux".
Currently, CVE_PRODUCT also detects vulnerabilities where the vendor is "visionsoft",
which are unrelated to the "audit" in this recipe.
https://www.opencve.io/cve?vendor=visionsoft&product=audit
In addition, all the vulnerabilities currently detected in "audit" have the vendor of "visionsoft" or "linux".
Therefore, fix "audit" set in CVE_PRODUCT to "linux:audit".
Signed-off-by: Shinji Matsunaga <shin.matsunaga@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit e87e51da49fe121be8f6dd4cec3263a345f2f876)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
meta-oe/recipes-security/audit/audit_4.0.2.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-oe/recipes-security/audit/audit_4.0.2.bb b/meta-oe/recipes-security/audit/audit_4.0.2.bb
index 0086f8db69..8a080eb709 100644
--- a/meta-oe/recipes-security/audit/audit_4.0.2.bb
+++ b/meta-oe/recipes-security/audit/audit_4.0.2.bb
@@ -99,3 +99,5 @@ do_install:append() {
# Create /var/spool/audit directory for audisp-remote
install -d -m 0700 ${D}${localstatedir}/spool/audit
}
+
+CVE_PRODUCT = "linux:audit"
next prev parent reply other threads:[~2025-11-13 6:20 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-13 6:18 [oe][meta-oe][scarthgap][PATCH 01/38] evtest: upgrade 1.35 -> 1.36 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 02/38] xrdp: upgrade 0.9.19 -> 0.9.20 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 03/38] xmlsec1: upgrade 1.3.4 -> 1.3.5 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 04/38] xdg-desktop-portal: update 1.18.1 -> 1.18.4 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 05/38] flatpak;xdg-desktop-portal: add missing runtime dependency on fuse3-utils ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 06/38] usbids: upgrade 2023.01.16 -> 2025.04.01 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 07/38] usbids: upgrade 2025.04.01 -> 2025.09.15 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 08/38] tbb: upgrade 2021.11.0 -> 2021.12.0 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 09/38] openldap: upgrade 2.6.7 -> 2.6.8 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 10/38] openldap: upgrade 2.6.8 -> 2.6.9 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 11/38] openldap: make license match spdx identifier ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 12/38] openldap: upgrade 2.6.9 -> 2.6.10 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 13/38] mcelog: upgrade 198 -> 199 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 14/38] mcelog: upgrade 199 -> 200 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 15/38] libiodbc: upgrade 3.52.15 -> 3.52.16 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 16/38] libgpiod: update to v1.6.5 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 17/38] libgpiod: update v2.1.2 -> v2.1.3 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 18/38] libbytesize: upgrade 2.10 -> 2.11 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 19/38] audit: upgrade 4.0.1 -> 4.0.2 ankur.tyagi85
2025-11-13 6:18 ` ankur.tyagi85 [this message]
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 21/38] audit: fix build when systemd is enabled ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 22/38] libbpf: upgrade 1.4.0 -> 1.4.2 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 23/38] libbpf: upgrade 1.4.2 -> 1.4.3 ankur.tyagi85
2025-11-13 6:18 ` [oe][meta-oe][scarthgap][PATCH 24/38] libbpf: upgrade 1.4.3 -> 1.4.5 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 25/38] libbpf: upgrade 1.4.5 -> 1.4.6 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 26/38] libbpf: upgrade 1.4.6 -> 1.4.7 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 27/38] openjpeg: upgrade 2.5.3 -> 2.5.4 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 28/38] neatvnc: upgrade 0.8.0 -> 0.8.1 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 29/38] jasper: upgrade 4.1.1 -> 4.1.2 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 30/38] libspiro: upgrade 20221101 -> 20230902 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 31/38] feh: upgrade 3.10.2 -> 3.10.3 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 32/38] redis-plus-plus: upgrade 1.3.11 -> 1.3.12 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 33/38] redis: upgrade 7.2.11 -> 7.2.12 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 34/38] redis: upgrade 6.2.20 -> 6.2.21 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 35/38] cryptsetup: upgrade 2.7.2 -> 2.7.3 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 36/38] cryptsetup: upgrade 2.7.3 -> 2.7.4 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 37/38] cryptsetup: upgrade 2.7.4 -> 2.7.5 ankur.tyagi85
2025-11-13 6:19 ` [oe][meta-oe][scarthgap][PATCH 38/38] botan: patch CVE-2024-34703 ankur.tyagi85
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251113061914.3756301-20-ankur.tyagi85@gmail.com \
--to=ankur.tyagi85@gmail.com \
--cc=openembedded-devel@lists.openembedded.org \
--cc=raj.khem@gmail.com \
--cc=shin.matsunaga@fujitsu.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox