Bug 14419

Summary: CVE management not documented
Product: [Documentation] Development Manual Reporter: Michael Opdenacker <michael.opdenacker>
Component: developmentAssignee: Michael Opdenacker <michael.opdenacker>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: michael.opdenacker, randy.macleod, richard.purdie
Version: unspecified   
Target Milestone: 3.4 M3   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Yes (doc changes required)

Description Michael Opdenacker 2021-06-02 14:30:19 UTC
The CVE_PRODUCT doesn't appear in the documentation and more generally CVE management doesn't seem to be documented.
Comment 1 Richard Purdie 2021-06-02 22:40:58 UTC
Add:

INHERIT += "cve-check"

to the configuration, then you can check CVE status with commands like:

bitbake -c cve_check groff python3 qemu rpm wget

We have a common include file to remove "known" CVE issues which can be included with:

bitbake -c cve_check groff -R conf/distro/include/cve-extra-exclusions.inc

CVE_PRODUCT defines the name used to match the recipe against the upstream NIST CVE database.

The CVE database is created by a recipe and stored in DL_DIR. You can look inside it using sqlite3, e.g.:

sqlite3 nvdcve_1.1.db .dump | grep CVE-2000-0803
Comment 2 Michael Opdenacker 2021-06-04 08:56:59 UTC
Thanks for the input!
Comment 3 Michael Opdenacker 2021-07-29 18:18:35 UTC
I'm think about documenting this in the Dev Manual, after license management (https://docs.yoctoproject.org/dev-manual/common-tasks.html#working-with-licenses).

A probably basic question here...
I added "wget" (which currently has an unpatched CVE) to my image. 
How can I look for CVEs in all the packages included in my image?

Are there any further recommendations for managing CVEs in a production project, like running the cve-check command daily on a cronjob or any better idea?

Thanks in advance
Michael.
Comment 4 Michael Opdenacker 2021-07-30 17:29:21 UTC
Found my own answer for the packages included in my image.
If "cve-check" is added to the configuration, unresolved CVEs will be displayed for the packages built by BitBake.

However, I'm still interested in thoughts about checking production images for vulnerability checks. Anything better than manual or cronjob checks?

Thank you in advance
Michael.
Comment 5 Michael Opdenacker 2021-07-30 17:38:41 UTC
Another question though:
How to check for vulnerabilities in my image without regenerating it, and without runing "bitbake -c cve_check" on individual package names?

Thanks in advance
Comment 6 Richard Purdie 2021-07-30 21:44:22 UTC
Ultimately we will generate an SBOM/manifest with the image and it would be good if we could run a new check of that manifest against the CVEs. That isn't currently implemented but should be and should perhaps be a new bug?
Comment 7 Michael Opdenacker 2021-08-02 14:03:15 UTC
Thanks for the advice!
I was about to open a new bug, but then I found this one:
https://bugzilla.yoctoproject.org/show_bug.cgi?id=8682

Could what's implemented in meta-security be a satisfactory solution, or would it be good to have a simpler one just for CVE checking?
Comment 8 Richard Purdie 2021-08-02 14:55:13 UTC
I think we'd need something specific for the CVE check and our manifests
Comment 9 Michael Opdenacker 2021-08-02 15:52:22 UTC
Thanks. I created the new bug on https://bugzilla.yoctoproject.org/show_bug.cgi?id=14495

My documentation patch is on its way to master.
I'll be able to close this bug soon :)