[Git][security-tracker-team/security-tracker][master] CVE-2021-34145 - CVE-2021-34148 in bluez-firmware have been introduced only...

Tobias Frost (@tobi) tobi at debian.org
Thu Dec 29 15:39:01 GMT 2022



Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3748b8c6 by Tobias Frost at 2022-12-29T16:38:00+01:00
CVE-2021-34145 - CVE-2021-34148 in bluez-firmware have been introduced only later, after bullseye release.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -114986,23 +114986,23 @@ CVE-2021-34149 (The Bluetooth Classic implementation on the Texas Instruments CC
 	NOT-FOR-US: Texas Instruments CC256XCQFN-EM
 CVE-2021-34148 (The Bluetooth Classic implementation in the Cypress WICED BT stack thr ...)
 	- bluez-firmware 1.2-8 (bug #1024356)
-	[bullseye] - bluez-firmware <no-dsa> (Non-free not supported)
-	[buster] - bluez-firmware <no-dsa> (Non-free not supported)
+	[bullseye] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
+	[buster] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
 	NOTE: https://github.com/RPi-Distro/bluez-firmware/commit/31ad68831357d2019624004f1f0846475671088f
 CVE-2021-34147 (The Bluetooth Classic implementation in the Cypress WICED BT stack thr ...)
 	- bluez-firmware 1.2-8 (bug #1024356)
-	[bullseye] - bluez-firmware <no-dsa> (Non-free not supported)
-	[buster] - bluez-firmware <no-dsa> (Non-free not supported)
+	[bullseye] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
+	[buster] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
 	NOTE: https://github.com/RPi-Distro/bluez-firmware/commit/31ad68831357d2019624004f1f0846475671088f
 CVE-2021-34146 (The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB do ...)
 	- bluez-firmware 1.2-8 (bug #1024356)
-	[bullseye] - bluez-firmware <no-dsa> (Non-free not supported)
-	[buster] - bluez-firmware <no-dsa> (Non-free not supported)
+	[bullseye] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
+	[buster] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
 	NOTE: https://github.com/RPi-Distro/bluez-firmware/commit/31ad68831357d2019624004f1f0846475671088f
 CVE-2021-34145 (The Bluetooth Classic implementation in the Cypress WICED BT stack thr ...)
 	- bluez-firmware 1.2-8 (bug #1024356)
-	[bullseye] - bluez-firmware <no-dsa> (Non-free not supported)
-	[buster] - bluez-firmware <no-dsa> (Non-free not supported)
+	[bullseye] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
+	[buster] - bluez-firmware <not-affected> (Affected firmware not present, introduced in bluez-firmware/1.2-5)
 	NOTE: https://github.com/RPi-Distro/bluez-firmware/commit/31ad68831357d2019624004f1f0846475671088f
 CVE-2021-34144 (The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SD ...)
 	NOT-FOR-US: Zhuhai Jieli



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3748b8c61ddf26e0c0a584da6612f8e19cc2808e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3748b8c61ddf26e0c0a584da6612f8e19cc2808e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221229/aec51a65/attachment.htm>


More information about the debian-security-tracker-commits mailing list