From patchwork Sun Nov 10 14:54:12 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Anuj Mittal X-Patchwork-Id: 179038 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp5471391ilf; Sun, 10 Nov 2019 06:55:07 -0800 (PST) X-Google-Smtp-Source: APXvYqzDrdbgJzGR6vsg5cjLLjhXuM06ZDjRwbEtsxAN4cqQmiI68wEn5kNOfJxnI9iq9A3IVyDh X-Received: by 2002:a63:e307:: with SMTP id f7mr24174289pgh.101.1573397707427; Sun, 10 Nov 2019 06:55:07 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1573397707; cv=none; d=google.com; s=arc-20160816; b=uBK2OU1RNPIpT7kFQTw26HPbTq/ElJeeAjJoCdyE+qE7yks6R4l3PidnVjyrGCBg5E 0cmSsMmhlZKD6DGQdvG4pJr1ehyz34v9le0boxUgSTojfMt4Q7Ahm6lwz4G+eLr5PuTT fYM51IEd71xXEixpAe/nD8/Tv2sgr2+fS2/E5T9MMZcdIO5mJdHB9tDFlSkB+1nDKSne bnKc4KdcAZ7Y0GXgl5BrDnEobTR/CoENg5kY4CRYWBRixQfLMrfFZE7p9xVLdlky63hK zyOuRwi/AEzpdwXw8tlw+nOadfbsBdPMoFs81UIJ3YAIckkE5N2MMeHdBqeDv9Q3DG6o lGew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :delivered-to; bh=8gSYsahjg9/0Ay7psYTEwQ0+ucWTSxmR+EWmajjcSds=; b=MIVDp4Ibs81kZvA1yYLPoVx58DWetGUCnQFJ68yYWrvUEK1b4I9j+eCs2kpgQfgzTp wNQGwf+GSortnjoFZ6aLCe3c+9/X79fC0tgGfKQI8bPMsH73JU1n9L3N4QJuQ6OfDtar 7YvO5JU58Fo1HQ2LBpUzZuYaRk2AtB9Zp9etyFCjB858w6BRp0tKW8n0YJLLcWWIMgwY WaY+cV12hvMa+zDWNwFaF1nWkzWFvk2P2ro7wmiAtaOWJNXNu1BG8jnKQSJCq8XrRQ92 UtSowI9t0ldE7bFw69SW2dElCQ/9uOdqdzCr34kMO5y8pkYD96gZpQQfhnQtaTNGz61n bPyQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id f9si14212896pgl.301.2019.11.10.06.55.06; Sun, 10 Nov 2019 06:55:07 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id E0A697F9C6; Sun, 10 Nov 2019 14:54:53 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mga14.intel.com (mga14.intel.com [192.55.52.115]) by mail.openembedded.org (Postfix) with ESMTP id 46AB77F96A for ; Sun, 10 Nov 2019 14:54:40 +0000 (UTC) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga008.jf.intel.com ([10.7.209.65]) by fmsmga103.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:41 -0800 X-IronPort-AV: E=Sophos;i="5.68,289,1569308400"; d="scan'208";a="197423076" Received: from wkwak-mobl1.gar.corp.intel.com (HELO anmitta2-mobl1.gar.corp.intel.com) ([10.252.8.93]) by orsmga008-auth.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:40 -0800 From: Anuj Mittal To: openembedded-core@lists.openembedded.org Date: Sun, 10 Nov 2019 22:54:12 +0800 Message-Id: <20191110145416.5171-4-anuj.mittal@intel.com> X-Mailer: git-send-email 2.21.0 In-Reply-To: <20191110145416.5171-1-anuj.mittal@intel.com> References: <20191110145416.5171-1-anuj.mittal@intel.com> MIME-Version: 1.0 Subject: [OE-core] [PATCH 3/7] libpng: whitelist CVE-2019-17371 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org From: Ross Burton This is actually a memory leak in gif2png 2.x, so whitelist it in the libpng recipe. Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Signed-off-by: Adrian Bunk Signed-off-by: Anuj Mittal --- meta/recipes-multimedia/libpng/libpng_1.6.37.bb | 3 +++ 1 file changed, 3 insertions(+) -- 2.21.0 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-multimedia/libpng/libpng_1.6.37.bb b/meta/recipes-multimedia/libpng/libpng_1.6.37.bb index 66af2f3d60..2ed87a8437 100644 --- a/meta/recipes-multimedia/libpng/libpng_1.6.37.bb +++ b/meta/recipes-multimedia/libpng/libpng_1.6.37.bb @@ -29,3 +29,6 @@ PACKAGES =+ "${PN}-tools" FILES_${PN}-tools = "${bindir}/png-fix-itxt ${bindir}/pngfix ${bindir}/pngcp" BBCLASSEXTEND = "native nativesdk" + +# CVE-2019-17371 is actually a memory leak in gif2png 2.x +CVE_CHECK_WHITELIST += "CVE-2019-17371" From patchwork Sun Nov 10 14:54:13 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Anuj Mittal X-Patchwork-Id: 179039 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp5471451ilf; Sun, 10 Nov 2019 06:55:13 -0800 (PST) X-Google-Smtp-Source: APXvYqwfyBKhXXH7RFc+a9dX8iLLAYc4+lBkrolbMQwbrw//4M59wip0opxJnCAGseWybf7sNvPT X-Received: by 2002:a17:90a:7109:: with SMTP id h9mr24489745pjk.54.1573397713067; Sun, 10 Nov 2019 06:55:13 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1573397713; cv=none; d=google.com; s=arc-20160816; b=By5GzUpWcaRINRv0xIAPHWilYqXTZHu8r9D5CstqhdB6xhnc+bEqQEblAO1uYiICWg eyjHk0ShVuY1QyyQsdcm8J3K+JiA5zhLkv4eQmmv/nioLOSVygksR2MK6kVOeB/dJFPr f8rN6m+Hl/kpUsHFga5Ut3tBUw7RCnzZXD8J0DqKH5ycko7cxsYOnBnC5KxRYY04bjSA 5fpn0tpE/zd7o9sD+KTEP1USRX2S+4WIEjLBdyNUSJ1hxTImE9TjMowYNiS/kcbGQTlY H2I8wUMHnmWlah/ysLg8tSJKIaIFeDkmr0haKrXPjpXckmHBB8t+LZAnURXTcagrAoVd atyQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :delivered-to; bh=JRSxWMXp3vMZmClmSbK45DcZQRWH9/T2G7Obz5GfNjI=; b=owvGs5Em9ZcZ8TAp39sB4gEcTDGF5aHp4eBXD39x6+yWg9NNL15UIbGs+AMX8lprfI 1R0Bem45L1rHWEMOvyJvLn41V5yaOF5AAW7XeFZI+0RvYAhzgww4vRGuD+rZsi6axe1Q yzZ9WLnhkX6MFvq0ex2VUD+x1AnfRMtrEflzLq6XrdUQz/taLKD/OHKNwacjC3xyly43 pUWhLkBD6lIa6yL170C3mKMIpW2+wbepct8a1rR18EaSO2yiLGx1CWt8LOgnCL3xuXft /0uEFRF/DiHWjPYuOWTF8UJ+z/6Adk7i3Zgkp75o3Ln7EGXaC+fRQ8TvqJ3BRAawAw9m 4iyA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id c9si13376134plz.431.2019.11.10.06.55.12; Sun, 10 Nov 2019 06:55:13 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 15F2A7FA0C; Sun, 10 Nov 2019 14:54:55 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mga14.intel.com (mga14.intel.com [192.55.52.115]) by mail.openembedded.org (Postfix) with ESMTP id 4495D7F97E for ; Sun, 10 Nov 2019 14:54:42 +0000 (UTC) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga008.jf.intel.com ([10.7.209.65]) by fmsmga103.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:43 -0800 X-IronPort-AV: E=Sophos;i="5.68,289,1569308400"; d="scan'208";a="197423079" Received: from wkwak-mobl1.gar.corp.intel.com (HELO anmitta2-mobl1.gar.corp.intel.com) ([10.252.8.93]) by orsmga008-auth.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:41 -0800 From: Anuj Mittal To: openembedded-core@lists.openembedded.org Date: Sun, 10 Nov 2019 22:54:13 +0800 Message-Id: <20191110145416.5171-5-anuj.mittal@intel.com> X-Mailer: git-send-email 2.21.0 In-Reply-To: <20191110145416.5171-1-anuj.mittal@intel.com> References: <20191110145416.5171-1-anuj.mittal@intel.com> MIME-Version: 1.0 Subject: [OE-core] [PATCH 4/7] procps: whitelist CVE-2018-1121 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org From: Ross Burton This CVE is about race conditions in 'ps' which make it unsuitable for security audits. As these race conditions are unavoidable ps shouldn't be used for security auditing, so this isn't a valid CVE. Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Signed-off-by: Adrian Bunk Signed-off-by: Anuj Mittal --- meta/recipes-extended/procps/procps_3.3.15.bb | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) -- 2.21.0 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-extended/procps/procps_3.3.15.bb b/meta/recipes-extended/procps/procps_3.3.15.bb index 9756db0e7b..f240e54fd8 100644 --- a/meta/recipes-extended/procps/procps_3.3.15.bb +++ b/meta/recipes-extended/procps/procps_3.3.15.bb @@ -4,9 +4,9 @@ the /proc filesystem. The package includes the programs ps, top, vmstat, w, kill HOMEPAGE = "https://gitlab.com/procps-ng/procps" SECTION = "base" LICENSE = "GPLv2+ & LGPLv2+" -LIC_FILES_CHKSUM="file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ - file://COPYING.LIB;md5=4cf66a4984120007c9881cc871cf49db \ - " +LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263 \ + file://COPYING.LIB;md5=4cf66a4984120007c9881cc871cf49db \ + " DEPENDS = "ncurses" @@ -64,3 +64,6 @@ python __anonymous() { d.setVarFlag('ALTERNATIVE_LINK_NAME', prog, '%s/%s' % (d.getVar('base_sbindir'), prog)) } +# 'ps' isn't suitable for use as a security tool so whitelist this CVE. +# https://bugzilla.redhat.com/show_bug.cgi?id=1575473#c3 +CVE_CHECK_WHITELIST += "CVE-2018-1121" From patchwork Sun Nov 10 14:54:14 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Anuj Mittal X-Patchwork-Id: 179040 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp5471555ilf; Sun, 10 Nov 2019 06:55:19 -0800 (PST) X-Google-Smtp-Source: APXvYqxtSbsXD1xpquHcEPlydsbo2y9P13w5Pz68NyJSyPUdCCdD5R7YdQRBSEfzOlg6ZNypmpeR X-Received: by 2002:a17:90a:8a12:: with SMTP id w18mr19362343pjn.51.1573397719449; Sun, 10 Nov 2019 06:55:19 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1573397719; cv=none; d=google.com; s=arc-20160816; b=tPGjJlCojTVywI81AGIPJO3E0QzXQJoUWyBXPvzUzQHvFnD3uEbG4RcDO8MP+QdARy ay7byVCUCpOpdoKGvypKNG82idg7PWyR7Nl/ydX0Gd/B9b2/ZC7RrhVnoCALERU6ylPP c3hAWnwM1IAQan50gAkQDKeVKy6UodfjmW3mRCiurQNXvjflEtHZ/SHB2jYseIG0WM0o 7aszt6/aKU2mcbzEE4KMT/889ZvoTosjb9+ozAc4QJSx5NUI9zVQpEDUHRfsNjBQJgYf 1N6dlogcElZFX3Wvs0rbkyCbuGD2eolzxcBVqBh29eOb1BP9gLUqXiuopCYBBWtRImgy nUlg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :delivered-to; bh=cgVGKRGY9v+RSr1nee2VzDIbo0UzR9veN9ZJMSit3Nw=; b=UzywiQwZbvguB2ALecBN4cOLklp42A+oOZFVNc4vVTO0wIJM10e5XYJ7rTV/JtAhqB hFjxSObdLWEk3KO/qG3n3k1ySa84M6Cj8XON0lc8zIO/cAsPq5c+pltIfxo7Gy/M9+yW XGJIjU0oScNk7bO3Po54kk10nFAC5c5sOwQZcxnKeXH5zUB/PIk2wtSe5chT8yQ1gKe9 h2PJjcJproFUnA55zNLdjusPL9q6P0oC7gCg48Y2gEPrN+WSKGYbNOUB7EVOqsFxuLX4 S5XwFZfe+kfXhKywi5wate5haiA53jvlWqOAfCx9aTyrk7IditOGjw/zb05cxi9aP2pa wYsw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id q12si14427659pgk.383.2019.11.10.06.55.19; Sun, 10 Nov 2019 06:55:19 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 3F7837FA15; Sun, 10 Nov 2019 14:54:56 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mga14.intel.com (mga14.intel.com [192.55.52.115]) by mail.openembedded.org (Postfix) with ESMTP id 624387F987 for ; Sun, 10 Nov 2019 14:54:44 +0000 (UTC) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga008.jf.intel.com ([10.7.209.65]) by fmsmga103.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:45 -0800 X-IronPort-AV: E=Sophos;i="5.68,289,1569308400"; d="scan'208";a="197423083" Received: from wkwak-mobl1.gar.corp.intel.com (HELO anmitta2-mobl1.gar.corp.intel.com) ([10.252.8.93]) by orsmga008-auth.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:44 -0800 From: Anuj Mittal To: openembedded-core@lists.openembedded.org Date: Sun, 10 Nov 2019 22:54:14 +0800 Message-Id: <20191110145416.5171-6-anuj.mittal@intel.com> X-Mailer: git-send-email 2.21.0 In-Reply-To: <20191110145416.5171-1-anuj.mittal@intel.com> References: <20191110145416.5171-1-anuj.mittal@intel.com> MIME-Version: 1.0 Subject: [OE-core] [PATCH 5/7] libsndfile1: whitelist CVE-2018-13419 X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org From: Ross Burton This is a memory leak that nobody else can replicate and has been rejected by upstream. Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Signed-off-by: Adrian Bunk Signed-off-by: Anuj Mittal --- meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb | 4 ++++ 1 file changed, 4 insertions(+) -- 2.21.0 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb index ffb45855a4..7855008f3d 100644 --- a/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb +++ b/meta/recipes-multimedia/libsndfile/libsndfile1_1.0.28.bb @@ -33,3 +33,7 @@ PACKAGECONFIG[alsa] = "--enable-alsa,--disable-alsa,alsa-lib" PACKAGECONFIG[regtest] = "--enable-sqlite,--disable-sqlite,sqlite3" inherit autotools lib_package pkgconfig + +# This can't be replicated and is just a memory leak. +# https://github.com/erikd/libsndfile/issues/398 +CVE_CHECK_WHITELIST += "CVE-2018-13419" From patchwork Sun Nov 10 14:54:15 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Anuj Mittal X-Patchwork-Id: 179041 Delivered-To: patch@linaro.org Received: by 2002:a92:38d5:0:0:0:0:0 with SMTP id g82csp5471659ilf; Sun, 10 Nov 2019 06:55:26 -0800 (PST) X-Google-Smtp-Source: APXvYqyeBFGmwZfrTYcx+3lG1euMh/zrO9xggUNFPjPwCVH40l7pzznSsNBEurFFXGlEb3M7KawA X-Received: by 2002:a17:902:6b0a:: with SMTP id o10mr14499262plk.15.1573397725866; Sun, 10 Nov 2019 06:55:25 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1573397725; cv=none; d=google.com; s=arc-20160816; b=JWqVVsps01QNl+yoEeW9pRK7flfY1bUd2egq6XKAB94YqPAEbUE9IxI5gVZzZ2dZuq othYMN4fVqr3EZLrqPnK5WDxb2uptsKx6GPpNnft7qHyyfpuk1ZrExEFRhlb/H4uTRYR PRG/8stnrhVM4UkViq/ZTN1sNT+HsnuYOZzoQTNbGm97Ym73YrXXGPM9ZvN3V/UF5TQl Oo0FLqr2kTkeUhnsHfWnFe686YrqbIRW1SPux2AcHAMnVvHCWeWELMhrJnIFTR38VaOS 4uNhZL1U+Fh4qBQ0PuFNQLzfxp+QeghURnxF4kkdenajXuhIkVzs6X64mgbhP2ArUAWN xWBQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=errors-to:sender:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :delivered-to; bh=uU5xiVS9S7nBVH9mD95W0jPFk6rPScsctPJb+B8ONms=; b=lLR4APTbA22Kv0iKmZwahj5zURYyR2vxYAAIhhbrLKQAvCWzhRruaUar7Fx3x9U23C mlFCjLXJ+9ML6mIYWN/t8gcuqAYxrYSnneIhP8DGSz99OZCnKwmjOXphRUuBwpnvZQRE UfZMNnFEx0KsToD4k4aikpqw5LL3Attp7vmjBTi/m5hTX8qu05eyeni+lWbWfLh3wNL7 2pRIpNtHFR2kvhe8nGYnHg2lMfqJrEulr/LfBYPHN4IQIbaGt7bp2MMLomqyv6+CSpxx TJhwTz5cBkcxkWonGizlFfaISadq8xqM5kWsQ/TBPT1VluuRXNcFR5dJn6wpvT87T/0G YTpQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Return-Path: Received: from mail.openembedded.org (mail.openembedded.org. [140.211.169.62]) by mx.google.com with ESMTP id k16si14238328pgb.183.2019.11.10.06.55.25; Sun, 10 Nov 2019 06:55:25 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) client-ip=140.211.169.62; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of openembedded-core-bounces@lists.openembedded.org designates 140.211.169.62 as permitted sender) smtp.mailfrom=openembedded-core-bounces@lists.openembedded.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=intel.com Received: from ec2-34-214-78-129.us-west-2.compute.amazonaws.com (localhost [127.0.0.1]) by mail.openembedded.org (Postfix) with ESMTP id 733277FA24; Sun, 10 Nov 2019 14:54:57 +0000 (UTC) X-Original-To: openembedded-core@lists.openembedded.org Delivered-To: openembedded-core@lists.openembedded.org Received: from mga14.intel.com (mga14.intel.com [192.55.52.115]) by mail.openembedded.org (Postfix) with ESMTP id 556B27F97E for ; Sun, 10 Nov 2019 14:54:46 +0000 (UTC) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from orsmga008.jf.intel.com ([10.7.209.65]) by fmsmga103.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:47 -0800 X-IronPort-AV: E=Sophos;i="5.68,289,1569308400"; d="scan'208";a="197423088" Received: from wkwak-mobl1.gar.corp.intel.com (HELO anmitta2-mobl1.gar.corp.intel.com) ([10.252.8.93]) by orsmga008-auth.jf.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 10 Nov 2019 06:54:46 -0800 From: Anuj Mittal To: openembedded-core@lists.openembedded.org Date: Sun, 10 Nov 2019 22:54:15 +0800 Message-Id: <20191110145416.5171-7-anuj.mittal@intel.com> X-Mailer: git-send-email 2.21.0 In-Reply-To: <20191110145416.5171-1-anuj.mittal@intel.com> References: <20191110145416.5171-1-anuj.mittal@intel.com> MIME-Version: 1.0 Subject: [OE-core] [PATCH 6/7] libpam: set CVE_PRODUCT X-BeenThere: openembedded-core@lists.openembedded.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Patches and discussions about the oe-core layer List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: openembedded-core-bounces@lists.openembedded.org Errors-To: openembedded-core-bounces@lists.openembedded.org From: Ross Burton Signed-off-by: Ross Burton Signed-off-by: Richard Purdie Signed-off-by: Adrian Bunk Signed-off-by: Anuj Mittal --- meta/recipes-extended/pam/libpam_1.3.1.bb | 2 ++ 1 file changed, 2 insertions(+) -- 2.21.0 -- _______________________________________________ Openembedded-core mailing list Openembedded-core@lists.openembedded.org http://lists.openembedded.org/mailman/listinfo/openembedded-core diff --git a/meta/recipes-extended/pam/libpam_1.3.1.bb b/meta/recipes-extended/pam/libpam_1.3.1.bb index 6b73f0a2fe..a2aa1ecd16 100644 --- a/meta/recipes-extended/pam/libpam_1.3.1.bb +++ b/meta/recipes-extended/pam/libpam_1.3.1.bb @@ -163,3 +163,5 @@ CONFFILES_${PN}-runtime += "${sysconfdir}/pam.d/common-account" CONFFILES_${PN}-runtime += "${sysconfdir}/security/limits.conf" UPSTREAM_CHECK_URI = "https://github.com/linux-pam/linux-pam/releases" + +CVE_PRODUCT = "linux-pam"