Bug 15780 - cve-check.bbclass reports CVE-2023-3079 against kernel
Summary: cve-check.bbclass reports CVE-2023-3079 against kernel
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: core (show other bugs)
Version: 5.2
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 5.3 M1
Assignee: Randy MacLeod
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2025-03-04 19:55 UTC by Robert Berger
Modified: 2025-05-20 16:53 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Berger 2025-03-04 19:55:06 UTC
linux-yocto-custom CVE-2023-3079     0.0      8.8      Unpatched  https://nvd.nist.gov/vuln/detail/CVE-2023-3079


https://nvd.nist.gov/vuln/detail/CVE-2023-3079:

Description

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

That's Chrome and not kernel.
Comment 1 Randy MacLeod 2025-03-06 15:41:11 UTC
Add to recipe as a skip, not applicable since the very complicated.
Comment 2 Ross Burton 2025-03-06 15:47:36 UTC
For reference, the CPE says:

  Affects cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

So affects all Linux systems,

  Running on/with cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

I can't see a sensible way of handling this as the kernel recipe doesn't know if chrome is being used, and in this specific case it's entirely a chrome issue.

You could argue with NVD about that CPE, but the easy fix is to explicitly CVE_STATUS it away.