Skip to content

CVE checker finding 700+ CVEs for linux-tegra (most are false-positives) #830

Answered by elPrac
bhagen55 asked this question in Q&A
Discussion options

You must be logged in to vote

First, cve-checker will use the NIC database to create the report and will use the bitbake recipes for that so this bbclass will compare whatever you set as virtual/kernel against the CVE database, now, this doesn't means that all 700 CVEs applies to you because you don't use all the features or drivers that where reported for that kernel version. Also notice that from the report you will find not only kernel related CVEs, again cve-checker uses all bb-recipes so you will find CVEs for common packages like coreutils, more info here -> https://wiki.yoctoproject.org/wiki/Security

You can easily know if package CVEs applies to you because yo can compare against the pkg-manifest but for kerne…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@madisongh
Comment options

@bhagen55
Comment options

Answer selected by bhagen55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants