summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2022-0998
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2022-03-25 20:49:54 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2022-03-25 20:49:54 +0100
commit799d3c586b6df4d41fccd5fc2ff796a087c26329 (patch)
tree58859fea1691e870e5406a47cbb0c08c1e4582e6 /retired/CVE-2022-0998
parente3e90ffdadf6bb9b0e7ff277a38879d594f49edd (diff)
Retire several CVEs
Diffstat (limited to 'retired/CVE-2022-0998')
-rw-r--r--retired/CVE-2022-099819
1 files changed, 19 insertions, 0 deletions
diff --git a/retired/CVE-2022-0998 b/retired/CVE-2022-0998
new file mode 100644
index 00000000..7ef46ebb
--- /dev/null
+++ b/retired/CVE-2022-0998
@@ -0,0 +1,19 @@
+Description: vdpa: clean up get_config_size ret value handling
+References:
+ https://lore.kernel.org/netdev/20220123001216.2460383-13-sashal@kernel.org/
+ https://bugzilla.redhat.com/show_bug.cgi?id=2057506
+Notes:
+ carnil> CONFIG_VHOST_VDPA not set in Debian.
+ bwh> The vhost vDPA backend was introduced in 5.7.
+ bwh> The change in 5.17 is described as only clean up, while the actual
+ bwh> fix was commit 3ed21c1451a1, already included in all vulnerable
+ bwh> branches.
+Bugs:
+upstream: released (5.16-rc6) [3ed21c1451a14d139e1ceb18f2fa70865ce3195a]
+5.10-upstream-stable: released (5.10.88) [51f6302f81d243772047a74ffeceddfb11c964d5]
+4.19-upstream-stable: N/A "Vulnerable code not present"
+4.9-upstream-stable: N/A "Vulnerable code not present"
+sid: released (5.15.15-1)
+5.10-bullseye-security: released (5.10.92-1)
+4.19-buster-security: N/A "Vulnerable code not present"
+4.9-stretch-security: N/A "Vulnerable code not present"

© 2014-2024 Faster IT GmbH | imprint | privacy policy