From ad45f0beef22a6e1f31b61e0c2ff9968173e940b Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 22 Feb 2022 07:32:55 +0100 Subject: Track upstream commit for CVE-2021-4115/policykit-1 --- data/CVE/2021.list | 1 + 1 file changed, 1 insertion(+) (limited to 'data/CVE/2021.list') diff --git a/data/CVE/2021.list b/data/CVE/2021.list index 13bc719b4d..ccbb518166 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -4333,6 +4333,7 @@ CVE-2021-4115 [file descriptor leak allows an unprivileged user to cause a crash [stretch] - policykit-1 (Vulnerable code not present, patch introducing issue not backported) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2007534 NOTE: https://securitylab.github.com/advisories/GHSL-2021-077-polkit/ + NOTE: Fixed by: https://gitlab.freedesktop.org/polkit/polkit/-/commit/41cb093f554da8772362654a128a84dd8a5542a7 NOTE: https://gitlab.freedesktop.org/polkit/polkit/-/issues/141 NOTE: Issue Upstream introduced in 0.113 with https://gitlab.freedesktop.org/polkit/polkit/-/commit/bfa5036bfb93582c5a87c44b847957479d911e38 NOTE: Debian backported 0.113 commits in 0.105-26 -- cgit v1.2.3