It seems cve-check does not understand operator OR in JSON file's nodes field. Example CVE-2020-15778 which not fixed in OpenSSH release 8.3p1 (maybe never). CVE-check output: PACKAGE NAME: openssh PACKAGE VERSION: 8.3p1 CVE: CVE-2020-15778 CVE STATUS: Patched CVE SUMMARY: scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows." CVSS v2 BASE SCORE: 6.8 CVSS v3 BASE SCORE: 7.8 VECTOR: NETWORK MORE INFORMATION: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15778 $ wget https://nvd.nist.gov/feeds/json/cve/1.1/nvdcve-1.1-2020.json.gz "configurations" : { "CVE_data_version" : "4.0", "nodes" : [ { "operator" : "OR", "cpe_match" : [ { "vulnerable" : true, "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*", "versionEndExcluding" : "8.3" }, { "vulnerable" : true, "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:8.3:-:*:*:*:*:*:*" }, { "vulnerable" : true, "cpe23Uri" : "cpe:2.3:a:openbsd:openssh:8.3:p1:*:*:*:*:*:*" } ] } ] Non-existing version 8.3 is excluded but 8.3p1 is vulnerable.
There may be a duplicate of this bug. Ross is going to check.
Related to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14630 as the CVE expression parser doesn't quite work right.
When querying the CVE db used by cve_check, we can see that the name of the version stored in db is not the official release name : $ sqlite3 downloads/CVE_CHECK/nvdcve_1.1.db .dump | grep CVE-2020-15778 INSERT INTO NVD VALUES('CVE-2020-15778','** DISPUTED ** scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."','6.8','7.8','2023-02-24T19:43Z','NETWORK'); INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','8.3_p1','=','',''); INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','8.3','=','',''); INSERT INTO PRODUCTS VALUES('CVE-2020-15778','openbsd','openssh','','','8.3','<'); The database use the name 8.3_p1, cve_check use 8.3p1. I will propose the following patch: Modify cve_check to interpret _ in the version name from the DB correctly: * removed for updates (_p*). * replaced by - for release candidate (_rc*)
Fixed by: https://git.yoctoproject.org/poky/commit/?id=81740facf458a5a3326c0cfca20ebf75d8fe91d0