diff options
author | Ben Hutchings <ben@decadent.org.uk> | 2019-04-25 14:49:09 +0100 |
---|---|---|
committer | Ben Hutchings <ben@decadent.org.uk> | 2019-04-25 20:41:22 +0100 |
commit | 7daea8c3af8df8d1d1103505efed5eeaed0baf66 (patch) | |
tree | b067886f9a5bbda9d6e65aed33b585eafe6a4b49 /retired/CVE-2018-11987 | |
parent | 46564783906b28651bbf75e2770218de302c4e94 (diff) |
Mark CVE-2018-11987 as N/A for upstream Linux, and retire it
Diffstat (limited to 'retired/CVE-2018-11987')
-rw-r--r-- | retired/CVE-2018-11987 | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/retired/CVE-2018-11987 b/retired/CVE-2018-11987 new file mode 100644 index 00000000..462750d4 --- /dev/null +++ b/retired/CVE-2018-11987 @@ -0,0 +1,19 @@ +Description: Double-free in ion_system_heap.c +References: + https://bugzilla.redhat.com/show_bug.cgi?id=1661435 + https://www.codeaurora.org/security-bulletin/2018/12/03/december-2018-code-aurora-security-bulletin#_CVE-2018-11987 + https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=5e9ffcfa152ecb2832990c42fcd8a0f2e63c2c04 +Notes: + carnil> Affects potentially upstream as well in + carnil> drivers/staging/android/ion/ion_system_heap.c . For Debian the + carnil> code is not build so would be unimportant. + carnil> Possibly introduced in e7f63771b60e7802c5a9b437c5ab1a8e33a0bb35 (4.9-rc1)? + bwh> There doesn't seem to be any path to double-free in any upstream version. +Bugs: +upstream: N/A "Vulnerable code path not present" +4.19-upstream-stable: N/A "Vulnerable code path not present" +4.9-upstream-stable: N/A "Vulnerable code path not present" +3.16-upstream-stable: N/A "Vulnerable code path not present" +sid: N/A "Vulnerable code path not present" +4.9-stretch-security: N/A "Vulnerable code path not present" +3.16-jessie-security: N/A "Vulnerable code path not present" |