Wind River Support Network

HomeDefectsLIN1021-6870
Fixed

LIN1021-6870 : cve-check fetching on WRL21

Created: Nov 27, 2023    Updated: Jun 6, 2024
Resolved Date: May 22, 2024
Found In Version: 10.21.20.20
Fix Version: 10.21.20.22
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Build & Config

Description

cve-check documentation
[https://docs.yoctoproject.org/dev/dev-manual/vulnerabilities.html]

There is a new fetcher for NVD database, since the old API that WRL21 is using is been deprecated in 15th December 2023 and then the cve-check within WRL21 will stop receiving updates.

New fetcher was introduced in April, and there a few small changes within the cve-check format.
[https://github.com/openembedded/openembedded-core/commit/fb62c4c3dbca4e58f7ce6cf29d4b630a06411a97]

Information from NVD.
[https://nvd.nist.gov/developers/vulnerabilities]
[https://nvd.nist.gov/General/News/change-timeline]

 
Live chat
Online