{"@context":"https://spdx.org/rdf/3.0.1/spdx-context.jsonld","@graph":[{"type":"CreationInfo","@id":"_:CreationInfo0","created":"2011-04-05T23:00:00Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"CreationInfo","@id":"_:CreationInfo1","created":"2025-10-20T18:15:27Z","createdBy":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded"],"createdUsing":["http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0"],"specVersion":"3.0.1"},{"type":"Organization","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/agent/OpenEmbedded","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"OpenEmbedded"},{"type":"Tool","spdxId":"http://spdx.org/spdxdocs/bitbake-addba517-4804-5ae3-87c2-0c3a1a5812ba/bitbake/tool/oe-spdx-creator_1_0","creationInfo":"_:CreationInfo0","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias"}],"name":"oe-spdx-creator 1.0"},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/8f84cb882607384162ed33c1497b8fae5b94e2575d8e9bc1ee6cf42f56ef5155/relationship/3d42eb2885618ab122257c139b57544c","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/relationship/3d42eb2885618ab122257c139b57544c"}],"from":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64","relationshipType":"dependsOn","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/b7b44dbfe490fecf8967f993c3c724d9f6d853b150370bdb231096e8088110d8/nativesdk-qemu/UNIHASH/package/nativesdk-qemu-common"],"scope":"runtime"},{"type":"SpdxDocument","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/document/package-nativesdk-qemu-user-aarch64","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/doc/nativesdk-qemu/package-nativesdk-qemu-user-aarch64/nativesdk-qemu/UNIHASH/document/package-nativesdk-qemu-user-aarch64","https://rdf.openembedded.org/spdx/3.0/link-name":"fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d"}],"name":"package-nativesdk-qemu-user-aarch64","profileConformance":["build","core","security","simpleLicensing","software"],"rootElement":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64"]},{"type":"software_Package","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64","creationInfo":"_:CreationInfo1","description":"QEMU full user emulation binaries(aarch64)","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/package/nativesdk-qemu-user-aarch64"}],"externalIdentifier":[{"type":"ExternalIdentifier","externalIdentifierType":"cpe23","identifier":"cpe:2.3:*:*:qemu:10.0.6:*:*:*:*:*:*:*"}],"name":"nativesdk-qemu-user-aarch64","summary":"QEMU full user emulation binaries(aarch64)","software_primaryPurpose":"install","software_homePage":"http://qemu.org","software_packageVersion":"10.0.6"},{"type":"software_File","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64/file/1","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/package/nativesdk-qemu-user-aarch64/file/1"}],"name":"usr/local/oe-sdk-hardcoded-buildpath/sysroots/x86_64-tdxsdk-linux/usr/bin/qemu-aarch64","verifiedUsing":[{"type":"Hash","algorithm":"sha256","hashValue":"cf0aebbc511732ce18cccd7b7fd2342fd592fe9c43eb417bf091ce8c36fee1e7"}]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/relationship/06b21ea9f1c4bb4ca7dcbdf061fb0d60","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/relationship/06b21ea9f1c4bb4ca7dcbdf061fb0d60"}],"from":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64","relationshipType":"hasAssociatedVulnerability","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2007-0998","http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2018-18438","http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2023-1386","http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2023-2680"]},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/relationship/392c704a2623a38e81c441ed4993702e","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/relationship/392c704a2623a38e81c441ed4993702e"}],"from":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64","relationshipType":"contains","to":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64/file/1"]},{"type":"LifecycleScopedRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/relationship/3b7aeed22ccf161cb2da3fdc2af03ffe","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/relationship/3b7aeed22ccf161cb2da3fdc2af03ffe"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/build/recipe","relationshipType":"hasOutput","to":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64"],"scope":"build"},{"type":"Relationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/relationship/82d8b3058139c2a50a27a3944ad4867f","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/relationship/82d8b3058139c2a50a27a3944ad4867f"}],"from":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64","relationshipType":"hasDeclaredLicense","to":["http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/license/3_27_0/GPL-2_0-only_AND_LGPL-2_1-only"]},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/vex-not-affected/16fb6da68f38aed2796f0ae3ecdfd017","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/vex-not-affected/16fb6da68f38aed2796f0ae3ecdfd017"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2023-1386","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64"],"security_vexVersion":"1.0.0","security_impactStatement":"not an issue as per https://bugzilla.redhat.com/show_bug.cgi?id=2223985"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/vex-not-affected/6b5a0358589b64eb7314cd54a33d06cb","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/vex-not-affected/6b5a0358589b64eb7314cd54a33d06cb"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2018-18438","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64"],"security_vexVersion":"1.0.0","security_impactStatement":"The issues identified by this CVE were determined to not constitute a vulnerability."},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/vex-not-affected/b5a376f8c844d7262bdd0beb0bfb0040","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/vex-not-affected/b5a376f8c844d7262bdd0beb0bfb0040"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2023-2680","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64"],"security_vexVersion":"1.0.0","security_impactStatement":"RHEL specific issue.","security_justificationType":"vulnerableCodeNotPresent"},{"type":"security_VexNotAffectedVulnAssessmentRelationship","spdxId":"http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/vex-not-affected/f6fad3595994d77fe98b6356c967618a","creationInfo":"_:CreationInfo1","extension":[{"type":"https://rdf.openembedded.org/spdx/3.0/id-alias","https://rdf.openembedded.org/spdx/3.0/alias":"http://spdxdocs.org/openembedded-alias/by-doc-hash/fc334cf988b70b572531b4d3d933f06f32aa2931f1be47c5e32f4a326d6aee2d/nativesdk-qemu/UNIHASH/vex-not-affected/f6fad3595994d77fe98b6356c967618a"}],"from":"http://spdxdocs.org/openembedded-alias/by-doc-hash/0ebbcb18868e98ac21f4d126ee0c18224a419eb99d3824a83343b00be36689e2/nativesdk-qemu/UNIHASH/vulnerability/CVE-2007-0998","relationshipType":"doesNotAffect","to":["http://spdx.org/spdxdocs/nativesdk-qemu-73b50db1-68d9-511b-b396-0360258e2016/cbbbd362096706b85f042745ab16952d6381004d04e8ab847e7271caf06a0842/package/nativesdk-qemu-user-aarch64"],"security_vexVersion":"1.0.0","security_impactStatement":"The VNC server can expose host files uder some circumstances. We don't enable it by default.","security_justificationType":"vulnerableCodeNotPresent"}]}