-
Notifications
You must be signed in to change notification settings - Fork 602
[Medium] Patched edk2 CVE-2024-38796, CVE-2024-6129, CVE-2024-2511, and CVE-2024-4603.
#13266
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
SPECS/edk2/edk2.spec
Outdated
| Release: 6%{?dist} | ||
| Summary: UEFI firmware for 64-bit virtual machines | ||
| License: Apache-2.0 AND (BSD-2-Clause OR GPL-2.0-or-later) AND BSD-2-Clause-Patent AND BSD-3-Clause AND BSD-4-Clause AND ISC AND MIT AND LicenseRef-Fedora-Public-Domain | ||
| URL: http://www.tianocore.org |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If possible, please change the url to https.
SPECS/edk2/edk2.spec
Outdated
| Patch1000: CVE-2022-3996.patch | ||
| Patch1001: CVE-2024-6119.patch | ||
| Patch1002: vendored-openssl-1.1.1-Only-free-the-read-buffers-if-we-re-not-using-them.patch | ||
| Patch1003: CVE-2024-38796.patch |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please check if patches >= 1000 are conventionally put for openssl while patches below < 1000 are for regular edk2.
2d09806 to
aad1224
Compare
kgodara912
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good for next stage: buddy build pipeline.
4ced9bd to
274f44f
Compare
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
|
Could possible build/test this change on top of #12657 |
+1 |
arc9693
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. Except that you might want to top this over the PR Cameron mentioned as it conflicts with it: #12657
|
/azurepipelines run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
edk2 CVE-2024-38796, CVE-2024-6129, CVE-2024-2511, and CVE-2024-4603.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Waiting for a manually-ran PR check to finish: https://dev.azure.com/mariner-org/mariner/_build/results?buildId=803636&view=results.
| Patch1002: CVE-2024-4741.patch | ||
| Patch1003: CVE-2024-13176.patch | ||
| Patch1004: CVE-2024-2511.patch | ||
| Patch1005: CVE-2023-6129.patch |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@jykanase We should not take this 2023-6129 patch. It applies to powerpc.
jslobodzian
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Remove the PowerPC CVE fix and dispute it as N/A
|
PR moved to the dev branch in #13715. |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
patch edk2 for CVE-2024-38796
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology