<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>14419</bug_id>
          
          <creation_ts>2021-06-02 14:30:19 +0000</creation_ts>
          <short_desc>CVE management not documented</short_desc>
          <delta_ts>2021-08-03 15:40:41 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>9</classification_id>
          <classification>Documentation</classification>
          <product>Development Manual</product>
          <component>development</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>3.4 M3</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Michael Opdenacker">michael.opdenacker</reporter>
          <assigned_to name="Michael Opdenacker">michael.opdenacker</assigned_to>
          <cc>michael.opdenacker</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>richard.purdie</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Yes (doc changes required)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>90556</commentid>
    <comment_count>0</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-06-02 14:30:19 +0000</bug_when>
    <thetext>The CVE_PRODUCT doesn&apos;t appear in the documentation and more generally CVE management doesn&apos;t seem to be documented.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90558</commentid>
    <comment_count>1</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2021-06-02 22:40:58 +0000</bug_when>
    <thetext>Add:

INHERIT += &quot;cve-check&quot;

to the configuration, then you can check CVE status with commands like:

bitbake -c cve_check groff python3 qemu rpm wget

We have a common include file to remove &quot;known&quot; CVE issues which can be included with:

bitbake -c cve_check groff -R conf/distro/include/cve-extra-exclusions.inc

CVE_PRODUCT defines the name used to match the recipe against the upstream NIST CVE database.

The CVE database is created by a recipe and stored in DL_DIR. You can look inside it using sqlite3, e.g.:

sqlite3 nvdcve_1.1.db .dump | grep CVE-2000-0803</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>90577</commentid>
    <comment_count>2</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-06-04 08:56:59 +0000</bug_when>
    <thetext>Thanks for the input!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91061</commentid>
    <comment_count>3</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-07-29 18:18:35 +0000</bug_when>
    <thetext>I&apos;m think about documenting this in the Dev Manual, after license management (https://docs.yoctoproject.org/dev-manual/common-tasks.html#working-with-licenses).

A probably basic question here...
I added &quot;wget&quot; (which currently has an unpatched CVE) to my image. 
How can I look for CVEs in all the packages included in my image?

Are there any further recommendations for managing CVEs in a production project, like running the cve-check command daily on a cronjob or any better idea?

Thanks in advance
Michael.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91074</commentid>
    <comment_count>4</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-07-30 17:29:21 +0000</bug_when>
    <thetext>Found my own answer for the packages included in my image.
If &quot;cve-check&quot; is added to the configuration, unresolved CVEs will be displayed for the packages built by BitBake.

However, I&apos;m still interested in thoughts about checking production images for vulnerability checks. Anything better than manual or cronjob checks?

Thank you in advance
Michael.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91075</commentid>
    <comment_count>5</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-07-30 17:38:41 +0000</bug_when>
    <thetext>Another question though:
How to check for vulnerabilities in my image without regenerating it, and without runing &quot;bitbake -c cve_check&quot; on individual package names?

Thanks in advance</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91076</commentid>
    <comment_count>6</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2021-07-30 21:44:22 +0000</bug_when>
    <thetext>Ultimately we will generate an SBOM/manifest with the image and it would be good if we could run a new check of that manifest against the CVEs. That isn&apos;t currently implemented but should be and should perhaps be a new bug?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91080</commentid>
    <comment_count>7</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-08-02 14:03:15 +0000</bug_when>
    <thetext>Thanks for the advice!
I was about to open a new bug, but then I found this one:
https://bugzilla.yoctoproject.org/show_bug.cgi?id=8682

Could what&apos;s implemented in meta-security be a satisfactory solution, or would it be good to have a simpler one just for CVE checking?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91084</commentid>
    <comment_count>8</comment_count>
    <who name="Richard Purdie">richard.purdie</who>
    <bug_when>2021-08-02 14:55:13 +0000</bug_when>
    <thetext>I think we&apos;d need something specific for the CVE check and our manifests</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91087</commentid>
    <comment_count>9</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-08-02 15:52:22 +0000</bug_when>
    <thetext>Thanks. I created the new bug on https://bugzilla.yoctoproject.org/show_bug.cgi?id=14495

My documentation patch is on its way to master.
I&apos;ll be able to close this bug soon :)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>91092</commentid>
    <comment_count>10</comment_count>
    <who name="Michael Opdenacker">michael.opdenacker</who>
    <bug_when>2021-08-03 15:40:41 +0000</bug_when>
    <thetext>Documentation now available through
http://git.yoctoproject.org/cgit/cgit.cgi/yocto-docs/commit/?id=2b9199fe490cb3ec126bffc6518646194a94ace4

and at:
https://docs.yoctoproject.org/dev-manual/common-tasks.html#checking-for-vulnerabilities</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>