From 8956285224a2c2861849d957f6af612c371c8a89 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Fri, 26 Jul 2019 09:52:57 +0200 Subject: Retire CVE-2018-20854 --- retired/CVE-2018-20854 | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 retired/CVE-2018-20854 (limited to 'retired/CVE-2018-20854') diff --git a/retired/CVE-2018-20854 b/retired/CVE-2018-20854 new file mode 100644 index 000000000..718b7ef2a --- /dev/null +++ b/retired/CVE-2018-20854 @@ -0,0 +1,15 @@ +Description: phy: ocelot-serdes: fix out-of-bounds read +References: +Notes: + carnil> Driver intorduced in same upstream version as per 51f6b410fc22 + carnil> ("phy: add driver for Microsemi Ocelot SerDes muxing") so it is + carnil> disputable why this has a CVE. +Bugs: +upstream: released (4.20-rc1) [6acb47d1a318e5b3b7115354ebc4ea060c59d3a1] +4.19-upstream-stable: N/A "Vulnerable code introduced later" +4.9-upstream-stable: N/A "Vulnerable code introduced later" +3.16-upstream-stable: N/A "Vulnerable code introduced later" +sid: N/A "Vulnerable code introduced later" +4.19-buster-security: N/A "Vulnerable code introduced later" +4.9-stretch-security: N/A "Vulnerable code introduced later" +3.16-jessie-security: N/A "Vulnerable code introduced later" -- cgit v1.2.3