On Tue, Dec 21, 2021 at 3:34 AM Ernst Sjöstrand
<[email protected]> wrote:
>
> On Tue, 2021-12-21 at 14:07 +0100, Konrad Weihmann wrote:
> >
> > On 21.12.21 14:02, Ernst Sjöstrand wrote:
> > > Dropbear shares a lot of code with other SSH implementations, so this is
> > > a port of CVE-2018-20685 to dropbear.
> > >
> > > Reference:
> > > https://urldefense.com/v3/__https://github.com/mkj/dropbear/commit/8f8a3dff705fad774a10864a2e3dbcfa9779ceff__;!!BFCLnRDDbM3FOmw!qe9UYrBIPEc6nPIeOuTW0e0hW6_XwL0XE4vWFFUg-UeQcxixYMRQ__QllRTD9Iw88H1k2OWm0g$
> > >
> > > Signed-off-by: Ernst Sjöstrand <[email protected]>
> >
> > This is missing an Upstream-Status entry - in this case that should be
> > "Upstream-Status: Backport"
>
> Should that line go in the .patch file, the commit message or both?
> I guess both?

See the "Patch name convention and commit message" section at:

https://wiki.yoctoproject.org/wiki/Security

Thanks for helping out with CVE fixes!

Steve


> 
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#159919): 
https://lists.openembedded.org/g/openembedded-core/message/159919
Mute This Topic: https://lists.openembedded.org/mt/87876568/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to