[Git][security-tracker-team/security-tracker][master] Add references for commits for CVE-2021-3638/qemu

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Dec 31 09:11:22 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c287799c by Salvatore Bonaccorso at 2022-12-31T10:10:50+01:00
Add references for commits for CVE-2021-3638/qemu

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -110192,6 +110192,8 @@ CVE-2021-3638 (An out-of-bounds memory access flaw was found in the ATI VGA devi
 	[stretch] - qemu <not-affected> (Vulnerable code introduced in ATI VGA device emulation added later)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1979858
 	NOTE: https://lore.kernel.org/qemu-devel/CAA8xKjXkDwPYxSAeRb+2mfHRrbiL_kh9unVkemFXLfF68UXePA@mail.gmail.com
+	NOTE: Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/584acf34cb05f16e13a46d666196a7583d232616 (v4.1.0-rc0)
+	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/205ccfd7a5ec86bd9a5678b8bd157562fc9a1643 (v7.2.0-rc0)
 CVE-2021-36235 (An issue was discovered in Ivanti Workspace Control before 10.6.30.0.  ...)
 	NOT-FOR-US: Ivanti
 CVE-2021-36234 (Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 all ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c287799c0336b0b4e57219280927e221523c1deb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c287799c0336b0b4e57219280927e221523c1deb
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20221231/beda6e6d/attachment.htm>


More information about the debian-security-tracker-commits mailing list