linux-yocto-custom CVE-2023-3079 0.0 8.8 Unpatched https://nvd.nist.gov/vuln/detail/CVE-2023-3079 https://nvd.nist.gov/vuln/detail/CVE-2023-3079: Description Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) That's Chrome and not kernel.
Add to recipe as a skip, not applicable since the very complicated.
For reference, the CPE says: Affects cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* So affects all Linux systems, Running on/with cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* I can't see a sensible way of handling this as the kernel recipe doesn't know if chrome is being used, and in this specific case it's entirely a chrome issue. You could argue with NVD about that CPE, but the easy fix is to explicitly CVE_STATUS it away.
Patch sent: https://lore.kernel.org/openembedded-core/20250515190523.1014417-1-Randy.MacLeod@windriver.com/T/#u
Fix merged: https://git.openembedded.org/openembedded-core/commit/?id=22ef4d2d116afb9d603a05fb107dd9da0e74558b