From 4f3dcb43ea85a8c9937a3da0a23a8b098962b962 Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Thu, 20 Jan 2022 16:25:42 +0100 Subject: follow sec team and mark some CVEs of glibc as no-dsa --- data/CVE/list | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/data/CVE/list b/data/CVE/list index 1c0df6495a..905f5280cb 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -1579,11 +1579,13 @@ CVE-2022-23219 (The deprecated compatibility function clnt_create in the sunrpc - glibc 2.33-3 [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=22542 CVE-2022-23218 (The deprecated compatibility function svcunix_create in the sunrpc mod ...) - glibc 2.33-3 [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=28768 CVE-2022-23217 RESERVED @@ -11160,12 +11162,14 @@ CVE-2021-3999 [Off-by-one buffer overflow/underflow in getcwd()] - glibc [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=28769 CVE-2021-3998 [Unexpected return value from realpath() for too long results] RESERVED - glibc [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=28770 NOTE: https://patchwork.sourceware.org/project/glibc/patch/20220113055920.3155918-1-siddhesh@sourceware.org/ CVE-2021-3997 [Uncontrolled recursion in systemd's systemd-tmpfiles] -- cgit v1.2.3