Bug 10772

Summary: Automatic generation of CVE-reports
Product: [Build System, Metadata & Runtime] Security - Recipe Upgrade Reporter: Sona Sarmadi <sona.sarmadi>
Component: securityAssignee: Ross Burton <ross.burton>
Status: RESOLVED WONTFIX QA Contact:
Severity: enhancement    
Priority: Medium CC: akuster, bluelightning, clopez, liu.ming50, ross.burton
Version: 2.3   
Target Milestone: 4.99   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)
Attachments:
Description Flags
core-image-minimal-qemux86.cve
none
cve-checktool - Master none

Description Sona Sarmadi 2016-12-06 18:49:39 UTC
Schedule the cve-check tool in autobuilder to run weekly for master and 2.3 and create summarized report based on the log. 

Someone from the security team could be responsible to look at these report and file a bug for critical or e.g. for those with score > 7.0.
Comment 1 Mariano Lopez 2017-03-28 21:27:25 UTC
Unfortunately it seems cve-check-tool development has stopped, we need to check what other options do we have.
Comment 2 Armin Kuster 2017-03-29 14:57:54 UTC
(In reply to comment #1)
> Unfortunately it seems cve-check-tool development has stopped, we need to
> check what other options do we have.

Do you mean the upstream github repo that is sponsored by Intel and Intel no longer is interested in developing it any further?
Last commit was a month ago.
Comment 3 Ross Burton 2017-03-29 15:00:09 UTC
I've emailed the author to get a definitive answer on whether it's maintained or if there's an alternative, but he's been on leave.
Comment 4 Leonardo Sandoval Gonzalez 2017-04-13 18:44:13 UTC
2.3M4 is basically over, so moving to next milestone. Also, pending on maintainer's answer to define direction.
Comment 5 Leonardo Sandoval Gonzalez 2017-06-12 16:12:36 UTC
Per Ross recommendation, setting 2.4 as milestone.
Comment 6 Leonardo Sandoval Gonzalez 2017-07-17 14:15:14 UTC
Ross,
do you have any update from the maintainer?
Comment 7 Sona Sarmadi 2017-08-16 10:57:55 UTC
I think cve-check tool works fine. When building the core images a cve report is generated if cve-check tool is enabled:

tmp/deploy/images/qemux86/core-image-minimal-emux86-20170816072229.rootfs.cve

I always inherit the cve-check class when I build an image and check the result.
It would be good to schedule autobuilder to generate this report once in a while and save the report somewhere. We could then add the link to the Yocto security wiki.
Comment 8 Carlos Alberto Lopez Perez 2017-08-16 11:36:41 UTC
(In reply to comment #7)
> I think cve-check tool works fine. When building the core images a cve
> report is generated if cve-check tool is enabled:
> 
> tmp/deploy/images/qemux86/core-image-minimal-emux86-20170816072229.rootfs.cve
> 
> I always inherit the cve-check class when I build an image and check the
> result.
> It would be good to schedule autobuilder to generate this report once in a
> while and save the report somewhere. We could then add the link to the Yocto
> security wiki.

But can you trust what this tool generates? 

I have just tested now to build core-image-lsb from poky (branch pyro) and I included on the image the "sudo" recipe, which is still on version 1.8.19p2 and therefore affected by CVE-2017-1000367 <https://www.sudo.ws/alerts/linux_tty.html> 

I inherited cve-check and I simply got a file named core-image-lsb-genericx86-64.cve which simply contains "CVE database was updated on 2017-08-16 11:27:43 UTC" and nothing else.
Comment 9 Sona Sarmadi 2017-08-16 12:00:49 UTC
Created attachment 3945 [details]
core-image-minimal-qemux86.cve
Comment 10 Sona Sarmadi 2017-08-16 12:04:11 UTC
> But can you trust what this tool generates? 

No I can't trust 100% , but this is another issue :) The tool however detects some unpatched CVEs without big efforts (see the attached core-image-minimal-qemux86.cve file). We could start fixing them ...

We can of course try always to improve existing tools or replcae with better tools if available.
Comment 11 Carlos Alberto Lopez Perez 2017-08-16 12:15:56 UTC
(In reply to comment #9)
> Created attachment 3945 [details]
> core-image-minimal-qemux86.cve

Mmmmm.. it looks its not working for me at all as I don't get this.

Do I need to do something else than just setting "inherit cve-check" on the image recipe? Do i need to set something on local.conf ?
Comment 12 Ming Liu 2017-08-16 12:23:27 UTC
I think for some recipes you will need set CVE_PRODUCT, for example tiff.bb sets CVE_PRODUCT=libtiff, provided that the recipe name does not match the name in CVE database.
Comment 13 Armin Kuster 2017-08-16 17:25:08 UTC
(In reply to comment #11)
> (In reply to comment #9)
> > Created attachment 3945 [details]
> > core-image-minimal-qemux86.cve
> 
> Mmmmm.. it looks its not working for me at all as I don't get this.
> 
> Do I need to do something else than just setting "inherit cve-check" on the
> image recipe? Do i need to set something on local.conf ?

I just tried it. I add to my local.conf

inherit += "cve-check"

bitbake -k -c cve_check universe

should get you started.
Comment 14 Armin Kuster 2017-08-16 17:26:11 UTC
Created attachment 3946 [details]
cve-checktool - Master

Here are the current failures in master.
Comment 15 Carlos Alberto Lopez Perez 2017-08-17 11:48:14 UTC
(In reply to comment #13)
> (In reply to comment #11)
> > (In reply to comment #9)
> > > Created attachment 3945 [details]
> > > core-image-minimal-qemux86.cve
> > 
> > Mmmmm.. it looks its not working for me at all as I don't get this.
> > 
> > Do I need to do something else than just setting "inherit cve-check" on the
> > image recipe? Do i need to set something on local.conf ?
> 
> I just tried it. I add to my local.conf
> 
> inherit += "cve-check"
> 

This didn't worked for me. But adding instead to local.conf the line below worked:

INHERIT_append = " cve-check"



Quick example:

On branch pyro, with inherit += "cve-check" on local.conf I get:
$ bitbake -c cve_check avahi
[...]
ERROR: Task do_cve_check does not exist for target avahi /home/igalia/clopez/[...]/poky/meta/recipes-connectivity/avahi/avahi_0.6.32.bb:do_cve_check)
ERROR: Command execution failed: 1


But with INHERIT_append = " cve-check" on local.conf I get:
$ bitbake -c cve_check avahi
[...]
WARNING: avahi-0.6.32-r0 do_cve_check: Found unpatched CVE (CVE-2017-6519), for more information check /home/igalia/clopez/[...]/avahi/0.6.32-r0/cve/cve.log
Comment 16 Sona Sarmadi 2017-08-18 05:30:37 UTC
I add following line in conf/local.conf file: 

INHERIT += "cve-check"

and run: 
#   bitbake -c cve_check openssl 
#   bitbake core-image-sato
#   bitbake -k -c cve_check universe

This always work for me :)
Comment 17 Ross Burton 2017-08-29 15:19:40 UTC
Moving out of needinfo.  cve-check-tool is mostly abandoned but whilst we still have it in oe-core, it's the best we've got.
Comment 18 Armin Kuster 2017-08-29 15:58:19 UTC
(In reply to comment #17)
> Moving out of needinfo.  cve-check-tool is mostly abandoned but whilst we
> still have it in oe-core, it's the best we've got.

I will fork it and see where that leads me too ; )
Comment 19 Carlos Alberto Lopez Perez 2017-09-07 16:19:12 UTC
(In reply to comment #17)
> Moving out of needinfo.  cve-check-tool is mostly abandoned but whilst we
> still have it in oe-core, it's the best we've got.

Agreed.
I also think this is more than enough to start improving the quality of the Yocto releases in terms of security fixes.

I enabled it and it is reported dozens of unfixed CVEs on last stable (pyro).

Is there any plan to start fixing this issues reported on the next Yocto release? Could deploying a buildbot at https://autobuilder.yoctoproject.org/main/ that runs cve_check over universe be of help? Just an idea.
Comment 20 Armin Kuster 2017-09-08 15:54:05 UTC
(In reply to comment #19)
> (In reply to comment #17)
> > Moving out of needinfo.  cve-check-tool is mostly abandoned but whilst we
> > still have it in oe-core, it's the best we've got.
> 
> Agreed.
> I also think this is more than enough to start improving the quality of the
> Yocto releases in terms of security fixes.
> 
> I enabled it and it is reported dozens of unfixed CVEs on last stable (pyro).

Does not surprise me. What are your expectations?

> 
> Is there any plan to start fixing this issues reported on the next Yocto
> release?

The plan is to fix what folks submit. Yocto is not a commercial distro and does not have the funds nor resources to do everything. We rely heavily on the community to help. You are welcome to submit package updates or patches to address individual security vulnerabilities.

 Could deploying a buildbot at
> https://autobuilder.yoctoproject.org/main/ that runs cve_check over universe
> be of help? Just an idea.

There is a bug open for this but it at best will only highlight what is missing to the best the tools ability. It will still come down to folks doing the work to fix them.
Comment 21 Armin Kuster 2018-02-22 04:06:00 UTC
we can use OVAL files with runs on a target. openscap will create html reports. 
not sure about cve-chektool
Comment 22 Ross Burton 2019-07-25 15:05:24 UTC
We have tooling to generate the reports, but I don't think that OE/Yocto should be advertising what exploits are in the metadata.