aboutsummaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)AuthorFilesLines
2024-02-20cve reviews: more 6.7.1 and 6.7.2 reviewsHEADmasterGreg Kroah-Hartman4-488/+585
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20Publish CVE-2024-26581Greg Kroah-Hartman4-0/+177
Allocated to 60c0c230c6f0 ("netfilter: nft_set_rbtree: skip end interval element from gc") Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20Publish CVE-2023-52433Greg Kroah-Hartman4-0/+154
Allocated to 2ee52ae94baa ("netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction") Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20cve/published: some .empty files for directories to show up in gitGreg Kroah-Hartman2-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20scripts/cve_publish_json:Greg Kroah-Hartman1-1/+2
Switch off of the test server to the real one. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20justfile: change email address to the kernel.org oneGreg Kroah-Hartman1-2/+3
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20add some new reserved ids.Greg Kroah-Hartman600-0/+0
These are real. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20move testing data off to the side, we are going live!Greg Kroah-Hartman65-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20cve/allocated: allocate some 2023 idsGreg Kroah-Hartman1-0/+101
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20justfile: add some stats commandsGreg Kroah-Hartman1-1/+7
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20justfile: add basic stats functionGreg Kroah-Hartman1-0/+17
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20justfile: add a justfile to directoryGreg Kroah-Hartman1-0/+21
Documents and reminds us how to run the scripts for doing work. Uses the tool, 'just' as found at https://github.com/casey/just and included in your distro. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20finish 6.7.5 first passGreg Kroah-Hartman2-1934/+2063
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20more 6.7.x mboxes to reviewGreg Kroah-Hartman9-1772/+127093
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-20add 6.7.1 review and proposed commitsGreg Kroah-Hartman3-109281/+2789
2024-02-19add 6.7 mbox of patches for reviewGreg Kroah-Hartman2-0/+111053
2024-02-19add initial 6.7 proposed changes to reviewGreg Kroah-Hartman1-0/+205
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-19update cve json entries with latest bippy outputGreg Kroah-Hartman10-70/+10
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-19scripts/cve_create: don't creat a duplicate cveGreg Kroah-Hartman1-0/+7
Check the sha for an existing one before creating a new one. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-19scripts/cve_update: count lines removed properlyGreg Kroah-Hartman1-1/+1
Sometimes we want to just remove lines, so catch that in the diff Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-19add allocated range of cves that are "real"Greg Kroah-Hartman1-0/+500
Just for holding now, will be imported properly "soon" Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-19bippy: read from the linux.uuid file.Greg Kroah-Hartman2-22/+22
Also remove the unneeded platforms array as that's just overkill in the json file. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-18scripts/cve_update: don't set unbound checking until AFTER we check some things.Greg Kroah-Hartman1-3/+3
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-18scripts/cve_update: make sure TMPDIR is set properlyGreg Kroah-Hartman1-0/+5
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-17update cve entries with latest json and mbox file updatesGreg Kroah-Hartman14-50/+232
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-17bippy: fix up and allow -rc kernels to countGreg Kroah-Hartman1-6/+19
We need that for the logic. Also add initial support for listing the files affected, but that doesn't seem to be working properly, so don't add it to the json file just yet, but add it to the mbox. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-17bippy: fix up previous commit that wasn't intendedGreg Kroah-Hartman1-3/+5
It added program info, which isn't working yet, so remove it from the json array. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-17update cve entries with hopefully proper git json infoGreg Kroah-Hartman11-317/+485
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-17bippy: move git json to a different sectionGreg Kroah-Hartman1-1/+16
Based on reviews from the CVE developers Also add product field, as we know that. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16cve entries: update based on latest bippy changesGreg Kroah-Hartman20-132/+132
urls are shorter. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16bippy: make the urls shorterGreg Kroah-Hartman1-10/+24
Thanks to Konstantin for the hint! Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16update cve test items based on latest version of bippy.Greg Kroah-Hartman16-153/+165
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16cve: some more test cvesGreg Kroah-Hartman8-0/+384
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16bippy: some more mbox wording cleanupsGreg Kroah-Hartman1-5/+6
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16bippy: lots of updates for affected/unaffected json handlingGreg Kroah-Hartman1-11/+97
Most is now complete, looks much better. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16cve test entries updated with latest output from bippyGreg Kroah-Hartman16-98/+486
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16bippy: use my kernel.org address as that's what our cve record saysGreg Kroah-Hartman1-1/+1
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-16bippy: handle the git ranges properly and reference all commitsGreg Kroah-Hartman1-28/+120
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-15another test cve for examples.Greg Kroah-Hartman4-0/+144
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-14form_letters: add more information and responses.Greg Kroah-Hartman2-16/+32
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13cve_* scripts: minor shellcheck fixesGreg Kroah-Hartman2-3/+1
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13cve entries: update mbox filesGreg Kroah-Hartman7-7/+14
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13bippy: add another blank line to the mbox file.Greg Kroah-Hartman1-0/+1
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13cve entries: update mbox filesGreg Kroah-Hartman7-14/+77
based on latest output of bippy Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13cve_update: only update the files if something changedGreg Kroah-Hartman1-1/+32
Filter out unneeded bippy-VERSION lines, and only update the files if something really changed. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13tags: add some missing tagsGreg Kroah-Hartman1-0/+2
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-13bippy: support tags betterGreg Kroah-Hartman2-23/+383
And add some more info in the mbox output Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12updates for entries based on latest bippy versionGreg Kroah-Hartman14-84/+84
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12Merge branch 'master' of gitolite.kernel.org:/pub/scm/linux/security/vulnsGreg Kroah-Hartman4-0/+152
2024-02-12bippy: encode version into mbox headerGreg Kroah-Hartman1-1/+1
So we can track the info like we do in the json file. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12bippy: mbox cleanups and rewordingGreg Kroah-Hartman1-11/+11
Also message can be properly signed by git send-email now. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12tmp: commit some test files I was using for original validationGreg Kroah-Hartman4-0/+152
Might need them in the near future, commit to the tree so they don't get lost. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12updated cve entries based on fixes in bippyGreg Kroah-Hartman14-28/+21
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12bippy: fix up issue when vuln/fix is in same releaseGreg Kroah-Hartman1-2/+13
Also drop the From: line in the mbox Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12add a testing 2021 commitGreg Kroah-Hartman4-0/+136
More stress testing of versions detection, something is wrong... Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12reserve some 2021 testing idsGreg Kroah-Hartman10-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12updates for all published cves based on better version checkingGreg Kroah-Hartman12-22/+22
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12bippy: update to latest version that handles figuring out the root fix betterGreg Kroah-Hartman1-19/+33
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12bippy: fix up the version detectionGreg Kroah-Hartman7-7/+7
It kept picking up the version of the commit for the repo, not the file itself, which meant it was always being updated for no good reason. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12test cves: update bippy version used to generateGreg Kroah-Hartman6-6/+6
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12cve_publish_json: add comment about how to get a list of idsGreg Kroah-Hartman1-1/+2
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12scripts/cve_publish_json: script to publish the cve entriesGreg Kroah-Hartman1-0/+57
Stop typing this by hand and script it. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12more test records created to test filters and version information.Greg Kroah-Hartman18-2/+474
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-12scripts/bippy: add more fields to filter outGreg Kroah-Hartman1-0/+3
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-11update testing cves with new bippy output format.Greg Kroah-Hartman4-29/+57
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-11scripts/bippy: better changelog text and mbox outputGreg Kroah-Hartman1-3/+56
Strip out the signed-off-by crud from the changelog info, and make a much nicer mbox output and disclaimer. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-11scripts/bippy: generate a vuln list in text formGreg Kroah-Hartman1-8/+13
Start working on a better mbox format Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-11scripts/cve_update: add script to update all existing cve entriesGreg Kroah-Hartman1-0/+52
Makes it easier when releases happen on older kernels, and for testing. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-09add CVE-2023-1851Greg Kroah-Hartman4-0/+136
Test version year stuff and more version matching. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-09cve/published/2024/CVE-2024-0052.json: updateGreg Kroah-Hartman1-9/+3
Get the version info right. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-09bippy: parse versions properlyGreg Kroah-Hartman1-19/+292
Implement, and document, version parsing and matching. Much better than before, there might be some corner cases missing, but this is a good first start. And ugh, bash... Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-09update test json file with latest bippy outputGreg Kroah-Hartman1-4/+5
Has versions affected a bit better now... Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-09scripts/bippy: make the default status be "affected"Greg Kroah-Hartman1-0/+1
Makes the cve record look better, it's no longer "unknown" as we really do know what the versions are here. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-09bippy: start tracking the "fixes" tags betterGreg Kroah-Hartman1-3/+10
Not quite there yet, but getting closer... Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-08cve/published: update the generated .json and mbox test fileGreg Kroah-Hartman2-1/+35
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-08scripts: add initial cut for making a mbox fileGreg Kroah-Hartman2-6/+14
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-08bippy: fix up indentation issuesGreg Kroah-Hartman1-58/+66
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-02-08scripts: update version of bippyGreg Kroah-Hartman2-19/+70
Import latest verison of bippy with better command line handling Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31cve: publish a test exampleGreg Kroah-Hartman4-0/+60
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31scripts/cve_create: script to create a cveGreg Kroah-Hartman1-0/+104
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31cve: move a "published" id back to reserved state for testing.Greg Kroah-Hartman1-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31cve/schema: document the file format a bit better.Greg Kroah-Hartman2-1/+12
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31cve/schema: describe how the files in the cve directory will lookGreg Kroah-Hartman1-0/+57
Provide some documentation for how files will work in this directory Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31bippy: update with latest versionGreg Kroah-Hartman1-3/+9
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31Add some reserved 2023 cve idsGreg Kroah-Hartman11-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-31cve: use year dates for ids as we will have multiple yearsGreg Kroah-Hartman11-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-23cve/README: updated the readme with the needed infoGreg Kroah-Hartman1-1/+26
Describe what this directory is for. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-23cve: allocated: remove directory, wrong name.Greg Kroah-Hartman1-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-23cve/CVE_JSON_5.0_schema.json: add the json scheme we must follow for CVE entriesGreg Kroah-Hartman1-0/+1204
As copied from: https://github.com/CVEProject/cve-schema/blob/master/schema/v5.0/CVE_JSON_5.0_schema.json Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-23cves: moved allocated to reserved, wrong stateGreg Kroah-Hartman11-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-21published a test cveGreg Kroah-Hartman2-0/+0
Also, the term is "published" not "assigned" Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-21scripts/bippy: Fix up some array handlingGreg Kroah-Hartman1-4/+9
Can now output a valid JSON file that the tools will accept! Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-21scripts/bippy: incorrect case for some tagsGreg Kroah-Hartman1-2/+2
"dataType" and "dataVersion", not all lower case, the tools were rejecting it with an odd error just because of that. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-21cve: allocate some testing ids for us to useGreg Kroah-Hartman11-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-21add README for cve directoryGreg Kroah-Hartman1-0/+2
This is just testing CVE entries at this point in time, nothing is "live" yet, so don't panic... Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-21scripts/bippy: now output json dataGreg Kroah-Hartman1-23/+113
Finally output some json, in a "hopefully close" output format. Needs testing with the CVE testing server, and also needs a way to handle the "vulnerable" kernel versions somehow. Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19form_letter: add one that I know we will need.Greg Kroah-Hartman1-0/+16
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19README: Trivial update to test some processesLee Jones1-2/+2
Signed-off-by: Lee Jones <lee@kernel.org>
2024-01-19update the README fileGreg Kroah-Hartman1-1/+1
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19add sample CVE .json file to test againstGreg Kroah-Hartman1-0/+58
2024-01-19bippy: handle default command line arguments betterGreg Kroah-Hartman1-4/+2
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19add bippy scriptGreg Kroah-Hartman1-0/+136
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19cve: add the linux uuid for the cve projectGreg Kroah-Hartman1-0/+1
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19cve: set up directory structure for idsGreg Kroah-Hartman3-0/+0
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2024-01-19Add README to explain this repo.Greg Kroah-Hartman1-0/+13
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>