<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Yocto Project (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/yocto.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/yocto-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Yocto Project (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-31563 – In the Linux kernel, the following vulnerability has been resolved:

net: macb: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31563</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31563</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: macb: Use dev_consume_skb_any() to free TX SKBs  The napi_consume_skb() function is not intended to be called in an IRQ disabled context. However, after commit 6bc8a5098bf4 ("net: macb: Fix tx_ptr_lock locking"), the freeing of TX SKBs is performed with IRQs disabled. To resolve the following call trace, use dev_consume_skb…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23175 – In the Linux kernel, the following vulnerability has been resolved:

net: cpsw: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23175</guid>
    <pubDate>Sat, 14 Feb 2026 17:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23175</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: cpsw: Execute ndo_set_rx_mode callback in a work queue  Commit 1767bb2d47b7 ("ipv6: mcast: Don't hold RTNL for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP.") removed the RTNL lock for IPV6_ADD_MEMBERSHIP and MCAST_JOIN_GROUP operations. However, this change triggered the following call trace on my BeagleBone Black board:   WAR…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25626 – Yocto Project is an open source collaboration project that helps developers crea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25626</guid>
    <pubDate>Mon, 19 Feb 2024 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25626</strong></p>
  <p>Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows an attacker to perform a remote code execution in the server's shell via a craf…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9731 – In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Projec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9731</guid>
    <pubDate>Fri, 16 Jun 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9731</strong></p>
  <p>In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Source entry in an ipk package.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9731">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
