Part Number: AM5728
Tool/software: Linux
Hi,
In June there was a bunch of Kernel Vulnerabilities made public which can be summarized by the Term "TCP SACK PANIC". Details can be found here: https://access.redhat.com/security/vulnerabilities/tcpsack
These CVEs were adressed by some kernel patches which were also backported to earlier versions. Namely 4.19.55 containes them for the 4.19 LTS Release.
The just released SDK 6.00.00 contains Kernel 4.19.38 and from what I can tell also doesn't contain any patches for these issues (also no manual backports).
I have no problem with applying them myself for our product firmware. But I wanted to ask if there is a specific reason why TI didn't include them in the last release. Was it just a timing issue or does TI not see them as critical enough? Or (even better) do these vulnerabilities not apply to ARM based kernels? I couldn't find anything about it related to Sitara Products.
Regards,
Michael