[Secure-testing-commits] r48244 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Sat Jan 21 07:14:20 UTC 2017
Author: carnil
Date: 2017-01-21 07:14:19 +0000 (Sat, 21 Jan 2017)
New Revision: 48244
Modified:
data/CVE/list
Log:
Add CVE-2017-5552/qemu
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-01-21 07:11:21 UTC (rev 48243)
+++ data/CVE/list 2017-01-21 07:14:19 UTC (rev 48244)
@@ -31,6 +31,14 @@
[wheezy] - wordpress <not-affected> (wp_ajax_update_plugin function introduced in 4.2)
NOTE: https://core.trac.wordpress.org/ticket/37490
NOTE: https://core.trac.wordpress.org/changeset/38168
+CVE-2017-5552 [display: virtio-gpu-3d: memory leakage in virgl_resource_attach_backing; CVE for the memory consumption issue, not an information disclosure issue]
+ - qemu <unfixed>
+ [jessie] - qemu <not-affected> (Vulnerable code not present)
+ [wheezy] - qemu <not-affected> (Vulnerable code not present)
+ - qemu-kvm <not-affected> (Vulnerable code not present)
+ NOTE: https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg00154.html
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1415281
+ NOTE: Fixed by: http://git.qemu.org/?p=qemu.git;a=commit;h=33243031dad02d161225ba99d782616da133f689
CVE-2017-5538
NOT-FOR-US: Samsung Exynos
CVE-2017-5524
More information about the Secure-testing-commits
mailing list