[Git][security-tracker-team/security-tracker][master] Add CVE-2022-26353/qemu and update note for CVE-2021-3748

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Mar 14 05:58:45 GMT 2022



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6d7ff114 by Salvatore Bonaccorso at 2022-03-14T06:58:04+01:00
Add CVE-2022-26353/qemu and update note for CVE-2021-3748

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1592,8 +1592,14 @@ CVE-2022-26354 [vhost-vsock: missing virtqueue detach on error can lead to memor
 	- qemu <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2063257
 	NOTE: https://gitlab.com/qemu-project/qemu/-/commit/8d1b247f3748ac4078524130c6d7ae42b6140aaf
-CVE-2022-26353
+CVE-2022-26353 [virtio-net: map leaking on error during receive]
 	RESERVED
+	- qemu <unfixed>
+	[buster] - qemu <not-affected> (Original upstream fix for CVE-2021-3748 not applied)
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2063197
+	NOTE: https://lists.nongnu.org/archive/html/qemu-devel/2022-03/msg02438.html
+	NOTE: Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/bedd7e93d01961fcb16a97ae45d93acf357e11f6 (v6.2.0-rc0)
+	NOTE: Introduced by the original fix for CVE-2021-3748.
 CVE-2022-0835
 	RESERVED
 CVE-2022-0834
@@ -34241,6 +34247,7 @@ CVE-2021-3748 [virtio-net: heap use-after-free in virtio_net_receive_rcu]
 	- qemu 1:6.1+dfsg-6 (bug #993401)
 	[stretch] - qemu <postponed> (Fix along with a future DLA)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1998514
+	NOTE: When fixing this issue make sure to not open CVE-2022-26353
 CVE-2021-40319
 	RESERVED
 CVE-2021-40318



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d7ff11450d8881ec701eb9311d7c783d5c90b20

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d7ff11450d8881ec701eb9311d7c783d5c90b20
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220314/40226347/attachment.htm>


More information about the debian-security-tracker-commits mailing list