From dae559781b1b61b94ddd41f80943c61b9e2c0f48 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 11 Jan 2022 07:28:13 +0100 Subject: Add CVE-2021-4202 --- active/CVE-2021-4202 | 14 ++++++++++++++ 1 file changed, 14 insertions(+) create mode 100644 active/CVE-2021-4202 diff --git a/active/CVE-2021-4202 b/active/CVE-2021-4202 new file mode 100644 index 00000000..1f301fa7 --- /dev/null +++ b/active/CVE-2021-4202 @@ -0,0 +1,14 @@ +Description: Race condition in nci_request() leads to use after free while the device is getting removed +References: + https://bugzilla.redhat.com/show_bug.cgi?id=2036682 +Notes: + carnil> CONFIG_NFC_NCI not enabled in Debian. +Bugs: +upstream: released (5.16-rc2) [86cdf8e38792545161dbe3350a7eced558ba4d15, 48b71a9e66c2eab60564b1b1c85f4928ed04e406] +5.10-upstream-stable: released (5.10.82) [cb14b196d991c864ed2d1b6e79d68a7ce38e6538, 34e54703fb0fdbfc0a3cfc065d71e9a8353d3ac9] +4.19-upstream-stable: released (4.19.218) [62be2b1e7914b7340281f09412a7bbb62e6c8b67], (4.19.219) 2350cffd71e74bf81dedc989fdec12aebe89a4a5] +4.9-upstream-stable: released (4.9.291) [4a59a3681158a182557c75bacd00d184f9b2a8f5], (4.9.292) [57c076e64ab55adf556cc515914564d61979f7c2] +sid: released (5.15.5-1) +5.10-bullseye-security: needed +4.19-buster-security: needed +4.9-stretch-security: needed -- cgit v1.2.3