On 18.09.20 15:58, masashi.kudo@cybertrust.co.jp wrote: > Hi, Jan-san, Siemens team, > > There was some query to Siemens about the need of CVE-2020-25284 backporting. > > - CVE-2020-25284 is in rbd ( Ceph block device ). > - it is only fixed for v4.19 and later stable kernels > - Siemens has this built as a module in their 4.4-rt x86 config, but not their 4.19 one > > So the question from the Kernel Team is whether Siemens needs its backporting to 4.4-rt or not. > Not to my best knowledge. This is very likely an accidental choice. Is that the only config in our repo carrying rbd/ceph? The we should likely drop that, to be clear also in the future. Jan > Please take a look about the discussion at the IRC meeting yesterday. > > https://irclogs.baserock.org/meetings/cip/2020/09/cip.2020-09-17-09.00.log.html > > Best regards, > -- > M. Kudo > -- Siemens AG, Corporate Technology, CT RDA IOT SES-DE Corporate Competence Center Embedded Linux