Yocto Project Documentation
 help / color / mirror / Atom feed
From: Takayasu Ito <ypa.takayasu.ito@gmail.com>
To: Antonin Godard <antonin.godard@bootlin.com>, docs@lists.yoctoproject.org
Cc: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
Subject: Re: [docs] [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes
Date: Wed, 16 Apr 2025 07:34:23 +0900	[thread overview]
Message-ID: <a9fd9bfb-dee9-4e94-8a95-d5673a9fd18c@gmail.com> (raw)
In-Reply-To: <D976ZCV50JQR.3B8GAANQILPQ1@bootlin.com>

Hi Antonin,

I could not post the patch because I did not have the development environment with me due to machine trouble.

On 2025/04/15 20:56, Antonin Godard wrote:
> Hi Takayasu,
> 
> On Sat Apr 12, 2025 at 6:38 PM CEST, Takayasu Ito wrote:
>> Hi all.
>>
>> * CVEs that have been fixed but are not on the list
>>
>> < +   * -  ``gstreamer1.0``
>> < +     - :cve_nist:`2024-47606`
>> < +   * -  ``gstreamer1.0-plugins-base``
>> < +     - :cve_nist:`2024-47538`, :cve_nist:`2024-47541`, :cve_nist:`2024-47542`,  :cve_nist:`2024-47600`,
>> :cve_nist:`2024-47607`, :cve_nist:`2024-47615`, :cve_nist:`2024-47835`
>> < +   * -  ``gstreamer1.0-plugins-good``
>> < +     - :cve_nist:`2024-47537`, :cve_nist:`2024-47539`, :cve_nist:`2024-47540`, :cve_nist:`2024-47543`,
>> :cve_nist:`2024-47544`, :cve_nist:`2024-47545`, :cve_nist:`2024-47546`, :cve_nist:`2024-47596`, :cve_nist:`2024-47597`,
>> :cve_nist:`2024-47598`, :cve_nist:`2024-47599`, :cve_nist:`2024-47601`, :cve_nist:`2024-47602`, :cve_nist:`2024-47603`,
>> :cve_nist:`2024-47606`, :cve_nist:`2024-47613`, :cve_nist:`2024-47774`, :cve_nist:`2024-47775`, :cve_nist:`2024-47776`,
>> :cve_nist:`2024-47777`, :cve_nist:`2024-47778`, :cve_nist:`2024-47834`
>> see https://gstreamer.freedesktop.org/security/
>>
>> < +   * - ``openssh``
>> < +     - :cve_nist:`2025-26465`, :cve_nist:`2025-26466`
>> see https://www.openssh.com/txt/release-9.9p2
>>
>> < +   * - ``socat``
>> < +     - :cve_nist:`2024-54661`
>> see http://www.dest-unreach.org/socat/
>>
>> * CVEs already fixed in previous releases
>>
>>   > +   * - ``libssh2``
>>   > +     - :cve_nist:`2023-48795`
>>
>> The patch for CVE-2023-28795, which is no longer needed due to libssh2 upgrading to 1.11.1, was committed on 2024/01/24 and has
>> already been fixed at the time of the scarthgap release, so we do not consider it necessary to post it to this list of fixes.
>> see:
>> https://git.yoctoproject.org/poky/commit/meta/recipes-support/libssh2/libssh2?h=walnascar&id=3adac25f899054b7d1d8c14458a1a4cd310abbd7
>>
>>
>> * CVE numbers that should be changed in ascending order
>>
>>   > +   * - ``expat``
>>   > +     - :cve_nist:`2024-50602`, :cve_nist:`2024-8176`
>> < +   * - ``expat``
>> < +     - :cve_nist:`2024-8176`, :cve_nist:`2024-50602`
>>
>>
>>   > +   * - ``grub``
>>   > +     - :cve_nist:`2024-45781`, :cve_nist:`2024-45782`, :cve_nist:`2024-56737`, :cve_nist:`2024-45780`,
>> :cve_nist:`2024-45783`, :cve_nist:`2025-0624`, :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2025-0622`,
>> :cve_nist:`2024-45776`, :cve_nist:`2024-45777`, :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2024-45778`,
>> :cve_nist:`2024-45779`, :cve_nist:`2025-0677`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`,
>> :cve_nist:`2025-0689`, :cve_nist:`2025-0678`, :cve_nist:`2025-1125`
>> < +   * - ``grub``
>> < +     - :cve_nist:`2024-45774`, :cve_nist:`2024-45775`, :cve_nist:`2024-45776`, :cve_nist:`2024-45777`,
>> :cve_nist:`2024-45778`, :cve_nist:`2024-45779`, :cve_nist:`2024-45780`, :cve_nist:`2024-45781`, :cve_nist:`2024-45782`,
>> :cve_nist:`2024-45783`, :cve_nist:`2024-56737`, :cve_nist:`2025-0622`, :cve_nist:`2025-0624`, :cve_nist:`2025-0677`,
>> :cve_nist:`2025-0678`, :cve_nist:`2025-0684`, :cve_nist:`2025-0685`, :cve_nist:`2025-0686`, :cve_nist:`2025-0689`,
>> :cve_nist:`2025-0690`, :cve_nist:`2025-1118`, :cve_nist:`2025-1125`
>>
>>   > +   * - ``libarchive``
>>   > +     - :cve_nist:`2024-57970`, :cve_nist:`2025-25724`, :cve_nist:`2025-1632`
>> < +   * - ``libarchive``
>> < +     - :cve_nist:`2024-57970`, :cve_nist:`2025-1632`, :cve_nist:`2025-25724`
>>
>>   > +   * - ``libxml2``
>>   > +     - :cve_nist:`2025-24928`, :cve_nist:`2024-56171`
>> < +   * - ``libxml2``
>> < +     - :cve_nist:`2024-56171`, :cve_nist:`2025-24928`
>>
>>   > +   * - ``tiff``
>>   > +     - :cve_nist:`2023-52356`, :cve_nist:`2023-6228`, :cve_nist:`2023-6277`
>> < +   * - ``tiff``
>> < +     - :cve_nist:`2023-6277`, :cve_nist:`2023-52356`, :cve_nist:`2023-6228`
>>
>>   > +   * - ``vim``
>>   > +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`,
>> :cve_nist:`2025-26603`, :cve_nist:`2025-1215`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
>> < +   * - ``vim``
>> < +     - :cve_nist:`2024-45306`, :cve_nist:`2024-47814`, :cve_nist:`2025-1215`, :cve_nist:`2025-22134`, :cve_nist:`2025-24014`,
>> :cve_nist:`2025-26603`, :cve_nist:`2025-27423`, :cve_nist:`2025-29768`
> 
> Thanks!
> 
> Can you please send a patch on the mailing list with these additions? So that
> you take credit for the changes. Please also describe how you came up with this
> list.
> 
> Regards,
> Antonin
> 

-- 
Takayasu Ito
Yocto Project Ambassador
ypa.takayasu.ito@gmail.com



  reply	other threads:[~2025-04-15 22:34 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-28 13:07 [PATCH 00/11] Final release note updates for 5.2 Antonin Godard
2025-03-28 13:07 ` [PATCH 01/11] migration-guides/release-notes-5.2.rst: add the list of contributors Antonin Godard
2025-03-28 13:07 ` [PATCH 02/11] migration-guides/release-notes-5.2.rst: add recipe upgrades Antonin Godard
2025-03-28 13:07 ` [PATCH 03/11] migration-guides/release-notes-5.2.rst: add LICENSE recipe changes Antonin Godard
2025-03-28 13:07 ` [PATCH 04/11] migration-guides/release-notes-5.2.rst: add security fixes Antonin Godard
2025-04-12 16:38   ` [docs] " Takayasu Ito
2025-04-15 11:56     ` Antonin Godard
2025-04-15 22:34       ` Takayasu Ito [this message]
2025-04-16  7:27         ` Antonin Godard
2025-04-20 15:27           ` Takayasu Ito
2025-03-28 13:07 ` [PATCH 05/11] migration-guides/release-notes-5.2.rst: add an entry for addfragments Antonin Godard
2025-03-28 13:07 ` [PATCH 06/11] migration-guides/migration-5.2.rst: final update for 5.2 Antonin Godard
2025-03-28 13:07 ` [PATCH 07/11] ref-manual/system-requirements.rst: update list of supported distributions Antonin Godard
2025-03-28 13:07 ` [PATCH 08/11] poky.yaml.in: bump minimum required Python version to 3.9 Antonin Godard
2025-03-28 13:07 ` [PATCH 09/11] ref-manual/variables.rst: document the GRUB_MKIMAGE_OPTS variable Antonin Godard
2025-03-28 13:07 ` [PATCH 10/11] ref-manual/variables.rst: document the SPDX_PACKAGE_VERSION variable Antonin Godard
2025-03-28 13:07 ` [PATCH 11/11] migration-guides/{migration,release-note}-5.2: update for 5.2 release Antonin Godard
2025-03-28 16:03   ` [docs] " Quentin Schulz
2025-03-28 16:47     ` Richard Purdie
2025-03-31  8:32       ` Quentin Schulz
2025-04-03 15:39         ` Richard Purdie
2025-03-28 14:44 ` [docs] [PATCH 00/11] Final release note updates for 5.2 Yoann Congal
2025-03-28 14:49   ` Antonin Godard
2025-03-28 14:52     ` Yoann Congal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a9fd9bfb-dee9-4e94-8a95-d5673a9fd18c@gmail.com \
    --to=ypa.takayasu.ito@gmail.com \
    --cc=antonin.godard@bootlin.com \
    --cc=docs@lists.yoctoproject.org \
    --cc=thomas.petazzoni@bootlin.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox