Bug 8682

Summary: Implement a way to check for vulnerable software on running target
Product: [Build System, Metadata & Runtime] Security - Recipe Upgrade Reporter: Mariano Lopez <mariano.lopez>
Component: securityAssignee: New Comer Bugs <newcomer>
Status: RESOLVED WORKSFORME QA Contact:
Severity: enhancement    
Priority: Medium CC: akuster, bluelightning, randy.macleod
Version: unspecified   
Target Milestone: Future   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Yes (doc changes required)

Description Mariano Lopez 2015-11-11 22:37:23 UTC
When a target is deployed in the field, usually is never updated, not even for security fixes. What I'm proposing is to have a service in the target that checks the current packages and versions used, then compare with a list of vulnerable packages and versions; if the target is using a vulnerable software then notify the vendor/user. This won't automatically do the software update on the field but I think is a step in the right direction.
Comment 1 Saul Wold 2015-11-23 21:58:33 UTC
Also please review the existing meta-security layer which has some other 
runtime testing tools.
Comment 2 Armin Kuster 2018-02-22 04:00:25 UTC
there is a way of doing this. basically OVL files via openscap to run. this works. recipes in meta-security. Its generating the OVL files. This also creates html reports.
Comment 3 Randy MacLeod 2021-04-08 14:35:52 UTC
As Armin mentioned there is a solution in meta-security. There are other solutions provided by companies.