<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>15780</bug_id>
          
          <creation_ts>2025-03-04 19:55:06 +0000</creation_ts>
          <short_desc>cve-check.bbclass reports CVE-2023-3079 against kernel</short_desc>
          <delta_ts>2025-05-20 16:53:32 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>core</component>
          <version>5.2</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>5.3 M1</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Robert Berger">pokylinux</reporter>
          <assigned_to name="Randy MacLeod">randy.macleod</assigned_to>
          <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>ross.burton</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>101278</commentid>
    <comment_count>0</comment_count>
    <who name="Robert Berger">pokylinux</who>
    <bug_when>2025-03-04 19:55:06 +0000</bug_when>
    <thetext>linux-yocto-custom CVE-2023-3079     0.0      8.8      Unpatched  https://nvd.nist.gov/vuln/detail/CVE-2023-3079


https://nvd.nist.gov/vuln/detail/CVE-2023-3079:

Description

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

That&apos;s Chrome and not kernel.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101302</commentid>
    <comment_count>1</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-03-06 15:41:11 +0000</bug_when>
    <thetext>Add to recipe as a skip, not applicable since the very complicated.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101305</commentid>
    <comment_count>2</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2025-03-06 15:47:36 +0000</bug_when>
    <thetext>For reference, the CPE says:

  Affects cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

So affects all Linux systems,

  Running on/with cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

I can&apos;t see a sensible way of handling this as the kernel recipe doesn&apos;t know if chrome is being used, and in this specific case it&apos;s entirely a chrome issue.

You could argue with NVD about that CPE, but the easy fix is to explicitly CVE_STATUS it away.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101969</commentid>
    <comment_count>3</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-05-15 19:06:21 +0000</bug_when>
    <thetext>Patch sent:
https://lore.kernel.org/openembedded-core/20250515190523.1014417-1-Randy.MacLeod@windriver.com/T/#u</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>102001</commentid>
    <comment_count>4</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-05-20 16:53:32 +0000</bug_when>
    <thetext>Fix merged:
https://git.openembedded.org/openembedded-core/commit/?id=22ef4d2d116afb9d603a05fb107dd9da0e74558b</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>