summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2021-43267
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2021-12-18 09:39:42 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2021-12-18 09:39:42 +0100
commitf6271401dc5e4e4e63fc7377af8068301e3cb69f (patch)
tree020625a310797f046571dab67213376a2e79736f /retired/CVE-2021-43267
parent85b0a6c7ec4958ee2e91d65234972a4516af6829 (diff)
Retire some CVEs
Diffstat (limited to 'retired/CVE-2021-43267')
-rw-r--r--retired/CVE-2021-4326715
1 files changed, 15 insertions, 0 deletions
diff --git a/retired/CVE-2021-43267 b/retired/CVE-2021-43267
new file mode 100644
index 00000000..c997c5e6
--- /dev/null
+++ b/retired/CVE-2021-43267
@@ -0,0 +1,15 @@
+Description: tipc: fix size validations for the MSG_CRYPTO type
+References:
+ https://www.sentinelone.com/labs/tipc-remote-linux-kernel-heap-overflow-allows-arbitrary-code-execution/
+Notes:
+ carnil> Commit fixes 1ef6f7c9390f ("tipc: add automatic session key
+ carnil> exchange") in 5.10-rc1.
+Bugs:
+upstream: released (5.15) [fa40d9734a57bcbfa79a280189799f76c88f7bb0]
+5.10-upstream-stable: released (5.10.77) [0b1b3e086b0af2c2faa9938c4db956fe6ce5c965]
+4.19-upstream-stable: N/A "Vulnerable code introduced later"
+4.9-upstream-stable: N/A "Vulnerable code introduced later"
+sid: released (5.14.16-1)
+5.10-bullseye-security: released (5.10.84-1)
+4.19-buster-security: N/A "Vulnerable code introduced later"
+4.9-stretch-security: N/A "Vulnerable code introduced later"

© 2014-2024 Faster IT GmbH | imprint | privacy policy