| Summary: | libxml2: Upgrade to 2.9.3 to address several out of bounds reads in libxml2 | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Sona Sarmadi <sona.sarmadi> |
| Component: | core | Assignee: | Joshua Lock <joshuagloe> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium+ | CC: | akuster, meta.mr.watcher, meta.watcher, richard.purdie |
| Version: | unspecified | ||
| Target Milestone: | 1.8.2 | ||
| Hardware: | All | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Sona Sarmadi
2015-11-23 12:24:14 UTC
A 2.9.3 upgrade for master is good but for jethro you'll have to convince the jethro maintainer (Robert Yang) that an upgrade is safer than a number of patches. some of these have been or are in the middle of being addressed by bug 8641 there are more than just CVE fixes in this update. Also, IMHO, not all security issues need to be fixed if the are low enough. Ok, we just upgrade master and backport individual CVEs in all maintained branches which we believe are important. (In reply to comment #4) > Ok, we just upgrade master and backport individual CVEs in all maintained > branches which we believe are important. From an OSV point of view, we have different matrix to determine which CVE's get fixed. For OE/Yocto project, there may be a different set of standards. (In reply to comment #4) > Ok, we just upgrade master and backport individual CVEs in all maintained > branches which we believe are important. By 'we', do you mean the community? Looks like master is taken care of. http://cgit.openembedded.org/openembedded-core/commit/?id=88e68f25e1756988692108d4c15dfa8efc94e5e5 Yes Armin, I mean The Yocto Project Community. > From an OSV point of view, we have different matrix to determine which CVE's get fixed. What do you mean by “OSV”? > For OE/Yocto project, there may be a different set of standards. Do you think it would be better that The Yocto Project have clear process of which CVEs should get fixed? Maybe we should add this info to Yocto security wiki (as a guideline)? We can use NVD scoring (ex: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3660) and have goal to backport all CVS’s scored higher than 5.0 at least in those packages which are widely used. For CVEs which are not yet in NVD’s data base, we can use other data base such as: http://www.cvedetails.com/ patch set sent for jethro and fido http://patches.openembedded.org/patch/109267/ Patches are merged for jethro and pending a merge request for fido. Merged to Fido |