diff options
author | Salvatore Bonaccorso <carnil@debian.org> | 2022-11-14 08:41:41 +0100 |
---|---|---|
committer | Salvatore Bonaccorso <carnil@debian.org> | 2022-11-14 08:41:41 +0100 |
commit | f42238fbe48d94b714783fe543cddb40b987bd75 (patch) | |
tree | 1c72eb8eaa6d3eab6f5c3d785c8b57cd0b774719 /retired/CVE-2022-3977 | |
parent | aad4d37b91a089a1d9ba7a86fb377bfa14e3a2cd (diff) |
Retire CVE-2022-3977
Diffstat (limited to 'retired/CVE-2022-3977')
-rw-r--r-- | retired/CVE-2022-3977 | 15 |
1 files changed, 15 insertions, 0 deletions
diff --git a/retired/CVE-2022-3977 b/retired/CVE-2022-3977 new file mode 100644 index 00000000..00432b2e --- /dev/null +++ b/retired/CVE-2022-3977 @@ -0,0 +1,15 @@ +Description: use-after-free bug in mctp_sk_unhash in net/mctp/af_mctp.c +References: + https://bugzilla.redhat.com/show_bug.cgi?id=2142371 + https://www.openwall.com/lists/oss-security/2022/11/14/1 +Notes: + carnil> Introduced by 63ed1aab3d40 ("mctp: Add SIOCMCTP{ALLOC,DROP}TAG + carnil> ioctls for tag control") in 5.18-rc1. + carnil> Fixed as well in 6.0.2 for 6.0.y. +Bugs: +upstream: released (6.1-rc1) [3a732b46736cd8a29092e4b0b1a9ba83e672bf89] +5.10-upstream-stable: N/A "Vulnerable code not present" +4.19-upstream-stable: N/A "Vulnerable code not present" +sid: released (6.0.2-1) +5.10-bullseye-security: N/A "Vulnerable code not present" +4.19-buster-security: N/A "Vulnerable code not present" |