[Secure-testing-commits] r58824 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Dec 21 21:14:03 UTC 2017


Author: carnil
Date: 2017-12-21 21:14:03 +0000 (Thu, 21 Dec 2017)
New Revision: 58824

Modified:
   data/CVE/list
Log:
Remove incorrect note, turns out that was not true, further investigation pending

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-12-21 21:10:19 UTC (rev 58823)
+++ data/CVE/list	2017-12-21 21:14:03 UTC (rev 58824)
@@ -8373,8 +8373,6 @@
 	[jessie] - linux <not-affected> (Vulnerable code introduced later)
 	[wheezy] - linux <not-affected> (Vulnerable code introduced later)
 	NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/davem/net.git/commit/?id=95a762e2c8c942780948091f8f2a4f32fce1ac6f
-	NOTE: Starting with v4.14, this is exploitable by unprivileged users as long as
-	NOTE: the unprivileged_bpf_disabled sysctl isn't set.
 CVE-2016-10702 (Pebble Smartwatch devices through 4.3 mishandle UUID storage, which ...)
 	NOT-FOR-US: Pebble
 CVE-2016-10701 (In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists ...)




More information about the Secure-testing-commits mailing list