[Git][security-tracker-team/security-tracker][master] Reserve DLA-2827-1 for bluez
Sylvain Beucler (@beuc)
beuc at debian.org
Sat Nov 27 10:15:03 GMT 2021
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f319b815 by Sylvain Beucler at 2021-11-27T11:14:40+01:00
Reserve DLA-2827-1 for bluez
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -10471,7 +10471,6 @@ CVE-2021-41229 (BlueZ is a Bluetooth protocol stack for Linux. In affected versi
- bluez <unfixed> (bug #1000262)
[bullseye] - bluez <no-dsa> (Minor issue)
[buster] - bluez <no-dsa> (Minor issue)
- [stretch] - bluez <no-dsa> (Minor issue)
NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-3fqg-r8j5-f5xq
NOTE: Introduced by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=d939483328489fb835bb425d36f7c7c73d52c388 (4.0)
NOTE: Fixed by: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=e79417ed7185b150a056d4eb3a1ab528b91d2fc0
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[27 Nov 2021] DLA-2827-1 bluez - security update
+ {CVE-2019-8921 CVE-2019-8922 CVE-2021-41229}
+ [stretch] - bluez 5.43-2+deb9u5
[23 Nov 2021] DLA-2826-1 mbedtls - security update
{CVE-2018-9988 CVE-2018-9989 CVE-2020-36475 CVE-2020-36476 CVE-2020-36478 CVE-2021-24119}
[stretch] - mbedtls 2.4.2-1+deb9u4
=====================================
data/dla-needed.txt
=====================================
@@ -18,8 +18,6 @@ ansible
NOTE: 20210411: after that LTS. (apo)
NOTE: 20210426: https://people.debian.org/~apo/lts/ansible/
--
-bluez (Sylvain Beucler)
---
debian-archive-keyring
NOTE: https://lists.debian.org/debian-lts/2021/08/msg00037.html
NOTE: 20210920: Raphael answered. will backport today. (utkarsh)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f319b815dd9ef6ebf719c0a0b8906b484c7fda46
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f319b815dd9ef6ebf719c0a0b8906b484c7fda46
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20211127/22c38be9/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list