blob: 5deee40dd5f3b3374bdb187333d6fe9e1cbc13ec (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
|
Description: INTEL-SA-00435
References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html
Notes:
carnil> CVE-2020-12351, CVE-2020-12352 and CVE-2020-24490 are three
carnil> issues covered by a set of commits/patches sent upstream but
carnil> there is no clear association from the CVEs to the commits. So
carnil> duplicate this entry for now to all three CVEs.
carnil> The commits are:
carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-1-luiz.dentz@gmail.com/
carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-2-luiz.dentz@gmail.com/
carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-3-luiz.dentz@gmail.com/
carnil> https://lore.kernel.org/linux-bluetooth/20200806181714.3216076-4-luiz.dentz@gmail.com/
carnil> which are not yet in mainline, and
carnil> a2ec905d1e16 ("Bluetooth: fix kernel oops in
carnil> store_pending_adv_report") which is in 5.8 (and which was
carnil> backported to 5.7.13, 5.4.56 and 4.19.137).
carnil> The "fixed version" information in INTEL-SA-00435 is thus as
carnil> well contradictory as it mentions the issue to be fixed in 5.9
carnil> or later.
Bugs:
upstream:
4.19-upstream-stable:
4.9-upstream-stable:
sid:
4.19-buster-security:
4.9-stretch-security:
|