[Git][security-tracker-team/security-tracker][master] Track fixed version for some linux CVEs with unstable upload

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jan 18 20:12:35 GMT 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e3196191 by Salvatore Bonaccorso at 2023-01-18T21:12:07+01:00
Track fixed version for some linux CVEs with unstable upload

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1156,7 +1156,7 @@ CVE-2023-22281
 	RESERVED
 CVE-2023-0266 [ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF]
 	RESERVED
-	- linux <unfixed>
+	- linux 6.1.7-1
 	NOTE: https://git.kernel.org/linus/56b88b50565cd8b946a2d00b0c83927b7ebb055e
 CVE-2023-0265
 	RESERVED
@@ -1332,10 +1332,10 @@ CVE-2013-10011 (A vulnerability was found in aeharding classroom-engagement-syst
 CVE-2012-10005 (A vulnerability has been found in manikandan170890 php-form-builder-cl ...)
 	NOT-FOR-US: manikandan170890 php-form-builder-class
 CVE-2023-23455 (atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1. ...)
-	- linux <unfixed>
+	- linux 6.1.7-1
 	NOTE: https://git.kernel.org/linus/a2965c7be0522eaa18808684b7b82b248515511b
 CVE-2023-23454 (cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4  ...)
-	- linux <unfixed>
+	- linux 6.1.7-1
 	NOTE: https://git.kernel.org/linus/caa4b35b4317d5147b3ab0fbdc9c075c7d2e9c12
 CVE-2023-23453
 	RESERVED
@@ -2546,7 +2546,7 @@ CVE-2023-0180
 	RESERVED
 CVE-2023-0179 [netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits]
 	RESERVED
-	- linux <unfixed>
+	- linux 6.1.7-1
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://www.openwall.com/lists/oss-security/2023/01/13/2
 	NOTE: https://patchwork.ozlabs.org/project/netfilter-devel/patch/20230111212251.193032-4-pablo@netfilter.org/
@@ -2628,7 +2628,7 @@ CVE-2023-22908
 	RESERVED
 CVE-2023-0210
 	RESERVED
-	- linux <unfixed>
+	- linux 6.1.7-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	[buster] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/797805d81baa814f76cf7bdab35f86408a79d707
@@ -21184,7 +21184,7 @@ CVE-2022-3708 (The Web Stories plugin for WordPress is vulnerable to Server-Side
 	NOT-FOR-US: Web Stories plugin for WordPress
 CVE-2022-3707
 	RESERVED
-	- linux <unfixed>
+	- linux 6.1.7-1
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2137979
 	NOTE: https://lore.kernel.org/all/20221007013708.1946061-1-zyytlz.wz@163.com/
 CVE-2022-3706 (Improper authorization in GitLab CE/EE affecting all versions from 7.1 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e319619125b0bc024087cbbcd530c30eb5af354f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e319619125b0bc024087cbbcd530c30eb5af354f
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230118/659767ad/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list