<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>15656</bug_id>
          
          <creation_ts>2024-11-23 15:41:10 +0000</creation_ts>
          <short_desc>cve-check.bbclass reports REJECTED CVEs</short_desc>
          <delta_ts>2026-05-21 15:16:40 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>5.2</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>OBSOLETE</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>6.0</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Robert Berger">pokylinux</reporter>
          <assigned_to name="Ross Burton">ross.burton</assigned_to>
          <cc>ccasciato</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>richard.purdie</cc>
    
    <cc>ross.burton</cc>
    
    <cc>rybczynska</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>100255</commentid>
    <comment_count>0</comment_count>
    <who name="Robert Berger">pokylinux</who>
    <bug_when>2024-11-23 15:41:10 +0000</bug_when>
    <thetext>Is the cve-check.bblass supposed to include REJECTED CVEs?

This turned up while playing with the Yocto-CVE-Parser and some master branch:

https://github.com/ejaaskel/Yocto-CVE-Parser/issues/4#issuecomment-2493046767</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100305</commentid>
    <comment_count>1</comment_count>
    <who name="Marta Rybczynska">rybczynska</who>
    <bug_when>2024-11-28 15:40:27 +0000</bug_when>
    <thetext>It used to work, looks like a regression.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100306</commentid>
    <comment_count>2</comment_count>
    <who name="Marta Rybczynska">rybczynska</who>
    <bug_when>2024-11-28 15:41:05 +0000</bug_when>
    <thetext>However, an entry without CVSS at all is a valid one.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100321</commentid>
    <comment_count>3</comment_count>
    <who name="Yoann Congal">yoann.congal</who>
    <bug_when>2024-11-28 16:20:10 +0000</bug_when>
    <thetext>It&apos;s supposed to work.

Code is here: meta/recipes-core/meta/cve-update-nvd2-native.bb:
https://git.openembedded.org/openembedded-core/tree/meta/recipes-core/meta/cve-update-nvd2-native.bb?h=master#n339

I&apos;ll try to look at this one.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100327</commentid>
    <comment_count>4</comment_count>
    <who name="Yoann Congal">yoann.congal</who>
    <bug_when>2024-12-01 22:03:12 +0000</bug_when>
    <thetext>(In reply to Robert Berger from comment #0)
&gt; Is the cve-check.bblass supposed to include REJECTED CVEs?
&gt; 
&gt; This turned up while playing with the Yocto-CVE-Parser and some master
&gt; branch:
&gt; 
&gt; https://github.com/ejaaskel/Yocto-CVE-Parser/issues/4#issuecomment-2493046767

I&apos;ve tried with a full download of the NVD data. From the list of problematic CVEs in the above link, only CVE-2023-4134 is present. CVE-2023-4134 is not Rejected, maybe it&apos;s an error?
That CVE aside, Rejected CVEs look correctly removed for the database during the full-download.

What could have happen is that the NVD recently had a glitch (approximately the same time as this bug was reported).
Maybe the update marking these CVEs &quot;Rejected&quot; failed and the previous &quot;active&quot; state was kept?

@Robert, does it sound plausible?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100371</commentid>
    <comment_count>5</comment_count>
    <who name="Robert Berger">pokylinux</who>
    <bug_when>2024-12-06 15:29:35 +0000</bug_when>
    <thetext>Turns out that when building the latest version of the Poky, there are rejected CVEs in the report, and they don&apos;t have a severity score assigned to them.

Examples issues don&apos;t have a score assigned to them and were included in the summary (built from Poky master hash 273eb505cb11fbe0590da9c8fc06c76b4405bf8c):

CVE-2021-36217
CVE-2024-35325
CVE-2024-35326
CVE-2024-35328
CVE-2017-0605
CVE-2017-1000
CVE-2019-10124
CVE-2019-3892
CVE-2019-9457
CVE-2019-9466
CVE-2020-0255
CVE-2020-0435
CVE-2020-14353
CVE-2021-0447
CVE-2021-0448
CVE-2021-0937
CVE-2021-3587
CVE-2021-3894
CVE-2021-3896
CVE-2022-0644
CVE-2022-1836
CVE-2022-1966
CVE-2022-1972
CVE-2022-20424
CVE-2022-20565
CVE-2022-21505
CVE-2022-23816
CVE-2022-3522
CVE-2022-3531
CVE-2022-3532
CVE-2022-3535
CVE-2022-3542
CVE-2023-0047
CVE-2023-2248
CVE-2023-2483
CVE-2023-3117
CVE-2023-34255
CVE-2023-3865
CVE-2023-3866
CVE-2023-3867
CVE-2023-4128
CVE-2023-4134
CVE-2023-4563
CVE-2023-4610
CVE-2023-4881
CVE-2023-52575
CVE-2023-52630
CVE-2024-0584
CVE-2024-26639
CVE-2024-26650

What should the cve report created by the YP do with them by design?

---

If it&apos;s what you say, that the NVD recently had a glitch (approximately the same time as this bug was reported) - which is unlikely, since I built it a couple of times and someone else as well a couple of days later. We have a serious problem!

Maybe the update marking these CVEs &quot;Rejected&quot; failed and the previous &quot;active&quot; state was kept?

With my current build I don&apos;t see this issue anymore.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100383</commentid>
    <comment_count>6</comment_count>
    <who name="Robert Berger">pokylinux</who>
    <bug_when>2024-12-08 18:12:47 +0000</bug_when>
    <thetext>Wouldn&apos;t it be possible to add something like a checksum to the database fetch?
So we can see that it&apos;s invalid?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101180</commentid>
    <comment_count>7</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-02-20 16:13:42 +0000</bug_when>
    <thetext>Ross to add a comment.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101190</commentid>
    <comment_count>8</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2025-02-20 16:52:58 +0000</bug_when>
    <thetext>It looks like if we already have a CVE in our database but in an update later changes it to rejected, it will still be reported because we filter out rejected CVEs too early.

Note that the NVD database is basically useless at this point in time, so whilst we should fix this there are far bigger problems...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>105532</commentid>
    <comment_count>9</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2026-05-21 15:16:40 +0000</bug_when>
    <thetext>Obsolete, cve-check has been removed from 6.0.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>