Bug 15239 - cve-check corruption of cvss3 data
Summary: cve-check corruption of cvss3 data
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 4.2.3
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 5.1 M2
Assignee: Marta Rybczynska
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2023-10-17 09:12 UTC by Marta Rybczynska
Modified: 2024-08-08 15:00 UTC (History)
6 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Yes (doc changes required)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marta Rybczynska 2023-10-17 09:12:11 UTC
https://lists.yoctoproject.org/g/poky/message/13173 brings a report from a user showing a database with cvss3 all set to 0.0.

A complete re-download of the database fixed the issue.

It might be related to the fix https://git.openembedded.org/openembedded-core/commit/meta/recipes-core/meta/cve-update-nvd2-native.bb?id=61a5857efdcc0f49c69c0deb24fce99007aeef19

The database seems to be never updated after the fix applied. To be verified.
Comment 1 Yoann Congal 2024-03-28 15:01:22 UTC
Maybe fixed by "cve-update-nvd2-native: Fix CVE configuration update" [0].

And "cve-update-nvd2-native: Add an age threshold for incremental update"[1] may help to force the redownload without removing a file in DL_DIR.

[0]: https://git.yoctoproject.org/poky/commit/?id=c698cf6723f344ddb1a755b4a2a0996aefa851f4
[1]: https://git.yoctoproject.org/poky/commit/?id=19f27037b2b785673c8f68f19ea783856f732e4d
Comment 2 Randy MacLeod 2024-08-08 15:00:28 UTC
Closing based on Yoann's comment and lack of any follow-up. Reopen if needed.