Changelog 10 - Sensitive numbers and our CVE Tracker

Written on May 31, 2017 by harryyoud

Welcome to LineageOS’ biweekly review, where we go over changes in the last couple of weeks

Major changes since the 15th May

CVE tracker (again)

If you didn’t know, Google releases a set of security updates monthly, which fix a number of CVEs (security vulnerabilities). These aren’t always in the upper layers of Android, and are typically in the kernel.

Because of this, it can be difficult to record exactly which devices, as a developer, have been patched against particular vulnerabilities. OurCVE tracker, which was previously private is now publically accessible (as read-only), primarily for the use of developers not currently part of the LineageOS team who would like to patch their kernels against security vulnerabilities.

To clear up some confusion, to modify values here, you have to be signed into a GitHub account that is part of the LineageOS organization on GitHub - a privilege reserved for those who are part of our team.

Also bear in mind, that this does not analyse the kernel repository. The device maintainer must mark particular CVEs patched themselves.

Build roster

Added 14.1 devices

Changes to 14.1 devices

Changes to 13.0 devices