Bug 15780

Summary: cve-check.bbclass reports CVE-2023-3079 against kernel
Product: [Build System, Metadata & Runtime] OE-Core Reporter: Robert Berger <pokylinux>
Component: coreAssignee: Randy MacLeod <randy.macleod>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: meta.mr.watcher, meta.watcher, randy.macleod, ross.burton
Version: 5.2   
Target Milestone: 5.3 M1   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Robert Berger 2025-03-04 19:55:06 UTC
linux-yocto-custom CVE-2023-3079     0.0      8.8      Unpatched  https://nvd.nist.gov/vuln/detail/CVE-2023-3079


https://nvd.nist.gov/vuln/detail/CVE-2023-3079:

Description

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

That's Chrome and not kernel.
Comment 1 Randy MacLeod 2025-03-06 15:41:11 UTC
Add to recipe as a skip, not applicable since the very complicated.
Comment 2 Ross Burton 2025-03-06 15:47:36 UTC
For reference, the CPE says:

  Affects cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

So affects all Linux systems,

  Running on/with cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

I can't see a sensible way of handling this as the kernel recipe doesn't know if chrome is being used, and in this specific case it's entirely a chrome issue.

You could argue with NVD about that CPE, but the easy fix is to explicitly CVE_STATUS it away.