Re: [oe] [PATCH] [meta-oe] kernel-fitimage: Fix CVE-2021-27138

2021-02-21 Thread Scott Murray
On Sun, 21 Feb 2021, Klaus Heinrich Kiwi wrote: > >> CVE-2021-27138 > >> > >> Adjust the kernel-fitimage.bbclass accordingly to not use unit > >> addresses. In addition to fixing a CVE, this is also required before we > >> can bump U-Boot to 2021.4. > >> > >> Signed-off-by: Klaus Heinrich

Re: [oe] [PATCH] [meta-oe] kernel-fitimage: Fix CVE-2021-27138

2021-02-21 Thread Klaus Heinrich Kiwi
CVE-2021-27138 Adjust the kernel-fitimage.bbclass accordingly to not use unit addresses. In addition to fixing a CVE, this is also required before we can bump U-Boot to 2021.4. Signed-off-by: Klaus Heinrich Kiwi [snip] Please send this to the oe-core list since kernel-fitimage.bbclas

Re: [oe] [PATCH] [meta-oe] kernel-fitimage: Fix CVE-2021-27138

2021-02-21 Thread Scott Murray
On Sat, 20 Feb 2021, Klaus Heinrich Kiwi wrote: > Das U-Boot 2021.4-rc1 has the following commit: > > commit 3f04db891a353f4b127ed57279279f851c6b4917 > Author: Simon Glass > Date: Mon Feb 15 17:08:12 2021 -0700 > > image: Check for unit addresses in FITs > > Using un

[oe] [PATCH] [meta-oe] kernel-fitimage: Fix CVE-2021-27138

2021-02-20 Thread Klaus Heinrich Kiwi
Das U-Boot 2021.4-rc1 has the following commit: commit 3f04db891a353f4b127ed57279279f851c6b4917 Author: Simon Glass Date: Mon Feb 15 17:08:12 2021 -0700 image: Check for unit addresses in FITs Using unit addresses in a FIT is a security risk. Add a check for