summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2021-4001
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2021-12-18 09:39:42 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2021-12-18 09:39:42 +0100
commitf6271401dc5e4e4e63fc7377af8068301e3cb69f (patch)
tree020625a310797f046571dab67213376a2e79736f /retired/CVE-2021-4001
parent85b0a6c7ec4958ee2e91d65234972a4516af6829 (diff)
Retire some CVEs
Diffstat (limited to 'retired/CVE-2021-4001')
-rw-r--r--retired/CVE-2021-400117
1 files changed, 17 insertions, 0 deletions
diff --git a/retired/CVE-2021-4001 b/retired/CVE-2021-4001
new file mode 100644
index 00000000..ab0035dd
--- /dev/null
+++ b/retired/CVE-2021-4001
@@ -0,0 +1,17 @@
+Description: bpf: Fix toctou on read-only map's constant scalar tracking
+References:
+ https://bugzilla.redhat.com/show_bug.cgi?id=2025645
+ https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=353050be4c19e102178ccc05988101887c25ae53
+Notes:
+ carnil> Commit fixes a23740ec43ba ("bpf: Track contents of read-only
+ carnil> maps as scalars") introduced in 5.5-rc1.
+ carnil> For 5.15.y series fixed in 5.15.5.
+Bugs:
+upstream: released (5.16-rc2) [353050be4c19e102178ccc05988101887c25ae53]
+5.10-upstream-stable: released (5.10.83) [33fe044f6a9e8977686a6a09f0bf33e5cc75257e]
+4.19-upstream-stable: N/A "Vulnerable code introduced later"
+4.9-upstream-stable: N/A "Vulnerable code introduced later"
+sid: released (5.15.5-1)
+5.10-bullseye-security: released (5.10.84-1)
+4.19-buster-security: N/A "Vulnerable code introduced later"
+4.9-stretch-security: N/A "Vulnerable code introduced later"

© 2014-2024 Faster IT GmbH | imprint | privacy policy