Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

opensc: multiple security vulnerablities require backports? #874

Open
citypw opened this issue Sep 25, 2024 · 6 comments
Open

opensc: multiple security vulnerablities require backports? #874

citypw opened this issue Sep 25, 2024 · 6 comments

Comments

@citypw
Copy link

citypw commented Sep 25, 2024

There are multiple security vulnerabilities are fixed in OpenSC v0.26-rc1:

https://github.com/OpenSC/OpenSC/releases/tag/0.26.0-rc1

@kraj
Copy link
Contributor

kraj commented Sep 26, 2024

@citypw I see that its still in RC stage. Once 0.26 final is released, we need to upgrade the recipe.

@citypw
Copy link
Author

citypw commented Sep 26, 2024

@kraj do you have plan to backport it to other branches like Kirkstone? There are some security backports still missing in Kirkstone:
https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories#opensc-security-advisories

@kraj
Copy link
Contributor

kraj commented Sep 26, 2024

@kraj do you have plan to backport it to other branches like Kirkstone? There are some security backports still missing in Kirkstone: https://github.com/OpenSC/OpenSC/wiki/OpenSC-security-advisories#opensc-security-advisories

Usual policy is no major version upgrades into release branches. It will surely be in master when it happens.

@citypw
Copy link
Author

citypw commented Sep 27, 2024

I understand the point. I saw some branches like Kirkstone did the security backports for OpenSC previously:
https://github.com/openembedded/meta-openembedded/blob/kirkstone/meta-oe/recipes-support/opensc/opensc_0.22.0.bb#L17C1-L25C43

It's still missing a couple of known vulnerabilities with CVE numbers. I'm curious what's the backport criteria. Will all CVEs backport to the branches or just some CVEs with higher impact?

@kraj
Copy link
Contributor

kraj commented Sep 27, 2024

it really depends upon contributors.

@citypw
Copy link
Author

citypw commented Sep 28, 2024

Okidoki, a PR with two backports: #876

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants