From: akuster808 <akuster808@gmail.com>
To: "Marko, Peter" <Peter.Marko@siemens.com>,
"yocto@lists.yoctoproject.org" <yocto@lists.yoctoproject.org>
Subject: Re: [yocto] [meta-security][kirkstone][PATCH] tpm2-tss: ignore CVE-2023-22745
Date: Sun, 30 Jul 2023 09:11:43 -0400 [thread overview]
Message-ID: <68455719-76e2-e33b-358f-ef02cb4c59b1@gmail.com> (raw)
In-Reply-To: <AS1PR10MB5697B9C288B623749255AAE7FD07A@AS1PR10MB5697.EURPRD10.PROD.OUTLOOK.COM>
On 7/29/23 5:34 PM, Marko, Peter wrote:
> Hi Armin,
>
> Gentle ping to pick this commit to kirkstone.
merged. thanks.
-armin
>
> Thanks,
> Peter
>
>> -----Original Message-----
>> From: yocto@lists.yoctoproject.org <yocto@lists.yoctoproject.org> On Behalf Of Peter Marko via lists.yoctoproject.org
>> Sent: Friday, June 30, 2023 0:10
>> To: yocto@lists.yoctoproject.org
>> Cc: Marko, Peter (ADV D EU SK BFS1) <Peter.Marko@siemens.com>
>> Subject: [yocto] [meta-security][kirkstone][PATCH] tpm2-tss: ignore CVE-2023-22745
>>
>> From: Peter Marko <peter.marko@siemens.com>
>>
>> As already mentioned in upgrade commit, this CVE is fixed.
>> But cve_check still reports it as NVD DB was not updated.
>>
>> Signed-off-by: Peter Marko <peter.marko@siemens.com>
>> ---
>> meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_3.2.2.bb | 3 +++
>> 1 file changed, 3 insertions(+)
>>
>> diff --git a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_3.2.2.bb b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_3.2.2.bb
>> index 9b76c2f..4d2c911 100644
>> --- a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_3.2.2.bb
>> +++ b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_3.2.2.bb
>> @@ -88,3 +88,6 @@ FILES:${PN} = "\
>> ${sysconfdir}/sysusers.d"
>>
>> RDEPENDS:libtss2 = "libgcrypt"
>> +
>> +# This is patched in 3.2.2, NVD DB was not updated to reflect this backport
>> +CVE_CHECK_IGNORE += "CVE-2023-22745"
>> --
>> 2.30.2
>>
prev parent reply other threads:[~2023-07-30 13:11 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <176D40CC2C1720E8.4592@lists.yoctoproject.org>
2023-07-29 21:34 ` [yocto] [meta-security][kirkstone][PATCH] tpm2-tss: ignore CVE-2023-22745 Marko, Peter
2023-07-30 13:11 ` akuster808 [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=68455719-76e2-e33b-358f-ef02cb4c59b1@gmail.com \
--to=akuster808@gmail.com \
--cc=Peter.Marko@siemens.com \
--cc=yocto@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox