summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2022-3977
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2022-11-14 08:41:41 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2022-11-14 08:41:41 +0100
commitf42238fbe48d94b714783fe543cddb40b987bd75 (patch)
tree1c72eb8eaa6d3eab6f5c3d785c8b57cd0b774719 /retired/CVE-2022-3977
parentaad4d37b91a089a1d9ba7a86fb377bfa14e3a2cd (diff)
Retire CVE-2022-3977
Diffstat (limited to 'retired/CVE-2022-3977')
-rw-r--r--retired/CVE-2022-397715
1 files changed, 15 insertions, 0 deletions
diff --git a/retired/CVE-2022-3977 b/retired/CVE-2022-3977
new file mode 100644
index 00000000..00432b2e
--- /dev/null
+++ b/retired/CVE-2022-3977
@@ -0,0 +1,15 @@
+Description: use-after-free bug in mctp_sk_unhash in net/mctp/af_mctp.c
+References:
+ https://bugzilla.redhat.com/show_bug.cgi?id=2142371
+ https://www.openwall.com/lists/oss-security/2022/11/14/1
+Notes:
+ carnil> Introduced by 63ed1aab3d40 ("mctp: Add SIOCMCTP{ALLOC,DROP}TAG
+ carnil> ioctls for tag control") in 5.18-rc1.
+ carnil> Fixed as well in 6.0.2 for 6.0.y.
+Bugs:
+upstream: released (6.1-rc1) [3a732b46736cd8a29092e4b0b1a9ba83e672bf89]
+5.10-upstream-stable: N/A "Vulnerable code not present"
+4.19-upstream-stable: N/A "Vulnerable code not present"
+sid: released (6.0.2-1)
+5.10-bullseye-security: N/A "Vulnerable code not present"
+4.19-buster-security: N/A "Vulnerable code not present"

© 2014-2024 Faster IT GmbH | imprint | privacy policy