From ea20a0b721e3bca9a52e6cc6a90707b0a4e53016 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 22 Feb 2022 07:32:55 +0100 Subject: Track upstream commit for CVE-2021-4115/policykit-1 --- data/CVE/list.2021 | 1 + 1 file changed, 1 insertion(+) diff --git a/data/CVE/list.2021 b/data/CVE/list.2021 index 13bc719b4d..ccbb518166 100644 --- a/data/CVE/list.2021 +++ b/data/CVE/list.2021 @@ -4333,6 +4333,7 @@ CVE-2021-4115 [file descriptor leak allows an unprivileged user to cause a crash [stretch] - policykit-1 (Vulnerable code not present, patch introducing issue not backported) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2007534 NOTE: https://securitylab.github.com/advisories/GHSL-2021-077-polkit/ + NOTE: Fixed by: https://gitlab.freedesktop.org/polkit/polkit/-/commit/41cb093f554da8772362654a128a84dd8a5542a7 NOTE: https://gitlab.freedesktop.org/polkit/polkit/-/issues/141 NOTE: Issue Upstream introduced in 0.113 with https://gitlab.freedesktop.org/polkit/polkit/-/commit/bfa5036bfb93582c5a87c44b847957479d911e38 NOTE: Debian backported 0.113 commits in 0.105-26 -- cgit v1.2.3