[Git][security-tracker-team/security-tracker][master] Add todo item for CVE-2020-3702

Salvatore Bonaccorso carnil at debian.org
Wed Dec 9 21:38:26 GMT 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fd1f2574 by Salvatore Bonaccorso at 2020-12-09T22:37:14+01:00
Add todo item for CVE-2020-3702

It is not very clear if the very same CVE would then be used, but it was
asked to reconsider the entry as
https://lore.kernel.org/linux-wireless/CABvG-CVvPF++0vuGzCrBj8+s=Bcx1GwWfiW1_Somu_GVncTAcQ@mail.gmail.com/
is refering to it and mentioning issues on the Linux kernel side.

Needs some further investigation.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -66930,6 +66930,7 @@ CVE-2020-3704 (u'While processing invalid connection request PDU which is nonsta
 CVE-2020-3703 (u'Buffer over-read issue in Bluetooth peripheral firmware due to lack  ...)
 	NOT-FOR-US: Qualcomm components for Android
 CVE-2020-3702 (u'Specifically timed and handcrafted traffic can cause internal errors ...)
+	TODO: check, it might affect src:linux as pointed out in https://lore.kernel.org/linux-wireless/CABvG-CVvPF++0vuGzCrBj8+s=Bcx1GwWfiW1_Somu_GVncTAcQ@mail.gmail.com/
 	NOT-FOR-US: Snapdragon
 CVE-2020-3701 (Use after free issue while processing error notification from camx dri ...)
 	NOT-FOR-US: Qualcomm components for Android



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd1f2574a77b8af08d6ff8aad394c3b29cd507bf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd1f2574a77b8af08d6ff8aad394c3b29cd507bf
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201209/fd18761c/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list