summaryrefslogtreecommitdiffstats
path: root/active/CVE-2020-12351
blob: 3919f2510b71e257028faf528de0e9bd0ba40721 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Description: INTEL-SA-00435
References:
 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html
 https://github.com/google/security-research/security/advisories/GHSA-h637-c88j-47wq
Notes:
 carnil> CVE-2020-12351, CVE-2020-12352 and CVE-2020-24490 are three
 carnil> issues covered by a set of commits/patches sent upstream but
 carnil> there is no clear association from the CVEs to the commits. So
 carnil> duplicate this entry for now to all three CVEs.
 carnil> The commits are:
 carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-1-luiz.dentz@gmail.com/
 carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-2-luiz.dentz@gmail.com/
 carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-3-luiz.dentz@gmail.com/
 carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-4-luiz.dentz@gmail.com/
 carnil> which are not yet in mainline, and
 carnil> a2ec905d1e16 ("Bluetooth: fix kernel oops in
 carnil> store_pending_adv_report") which is in 5.8 (and which was
 carnil> backported to 5.7.13, 5.4.56 and 4.19.137). This commit fixes
 carnil> c215e9397b00 ("Bluetooth: Process extended ADV report event")
 carnil> which is in 4.19-rc1 but not backported to other stable series.
 carnil> The "fixed version" information in INTEL-SA-00435 is thus as
 carnil> well contradictory as it mentions the issue to be fixed in 5.9
 carnil> or later.
Bugs:
upstream: needed
4.19-upstream-stable: needed
4.9-upstream-stable: needed
sid: needed
4.19-buster-security: needed
4.9-stretch-security: needed

© 2014-2024 Faster IT GmbH | imprint | privacy policy