Re: [OE-core] gnupg CVE-2022-3515 #kirkstone

2024-06-18 Thread Clayton Casciato
sday, June 18, 2024 7:48 AM To: Clayton Casciato Cc: openembedded-core@lists.openembedded.org ; hongxu@windriver.com ; alex.kana...@gmail.com Subject: Re: [OE-core] gnupg CVE-2022-3515 #kirkstone On Fri, Jun 14, 2024 at 12:51 AM Clayton Casciato via lists.openembedde

Re: [OE-core] gnupg CVE-2022-3515 #kirkstone

2024-06-18 Thread Marta Rybczynska
On Fri, Jun 14, 2024 at 12:51 AM Clayton Casciato via lists.openembedded.org wrote: > Hello! > > "OE-core CVE metrics for kirkstone on Sun 09 Jun 2024 02:00:01 AM HST" > reports CVE-2022-3515 as > "unpatched", as do local builds with "cve-check".

[OE-core] gnupg CVE-2022-3515 #kirkstone

2024-06-13 Thread Clayton Casciato
Hello! "OE-core CVE metrics for kirkstone on Sun 09 Jun 2024 02:00:01 AM HST" reports CVE-2022-3515 as "unpatched", as do local builds with "cve-check". NIST lists GnuPG as vulnerable from 2.3.0 to 2.4.0, which is why this is reported as a CVE.