Yocto Project Discussions
 help / color / mirror / Atom feed
* Fixing vulnerabilities in glibc #yocto
@ 2019-12-09 13:48 milunj
  2019-12-09 17:24 ` [yocto] " Randy MacLeod
  2019-12-09 19:46 ` Khem Raj
  0 siblings, 2 replies; 3+ messages in thread
From: milunj @ 2019-12-09 13:48 UTC (permalink / raw)
  To: yocto

[-- Attachment #1: Type: text/plain, Size: 1165 bytes --]

My greeting to all
I am new on yocto project and yocto build environment is also new to me ...
My working task is removing  vulnerabilities from libc library...
The processor is based on arm5 while newer yoctos 2.7.x and 3.x. do not provide environment support for arm5 based processors.

The glibc vulnerabilities are fixed in the latest glibc 2.30 released. ( https://sourceware.org/ml/libc-alpha/2019-08/msg00029.html ) package while yocto 2.6.x  includes 2.28 package.
Also some of glibc vulnerabilities are patched in 2.6.4 (\oecore-thud-20.0.4.tar\oecore-thud-20.0.4\meta\recipes-core\glibc\glibc):

CVE-2016-10739
CVE-2018-19591
CVE-2019-6488
CVE-2019-7309
CVE-2019-9169
while there are some others those have not been patched:
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-3590
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2006-7254
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20796
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-9192

Does anyone know whether new vulnerability patches will be applied for yocto 2.6.5 and  when will be released yocto 2.6.5 ?
Thank you in advance
Milun

[-- Attachment #2: Type: text/html, Size: 2607 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-12-09 19:46 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-12-09 13:48 Fixing vulnerabilities in glibc #yocto milunj
2019-12-09 17:24 ` [yocto] " Randy MacLeod
2019-12-09 19:46 ` Khem Raj

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox