[Git][security-tracker-team/security-tracker][master] Add CVE-2023-2860/linux

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jun 29 06:55:49 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6c50f3b4 by Salvatore Bonaccorso at 2023-06-29T07:55:19+02:00
Add CVE-2023-2860/linux

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -131,6 +131,12 @@ CVE-2023-32339 (IBM Business Automation Workflow is vulnerable to cross-site scr
 	NOT-FOR-US: IBM
 CVE-2023-2996 (The Jetpack WordPress plugin before 12.1.1 does not validate uploaded  ...)
 	NOT-FOR-US: WordPress plugin
+CVE-2023-2860 [ipv6: sr: fix out-of-bounds read when setting HMAC data.]
+	- linux 5.19.11-1
+	[bullseye] - linux 5.10.148-1
+	[buster] - linux 4.19.260-1
+	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-CAN-18511/
+	NOTE: https://git.kernel.org/linus/84a53580c5d2138c7361c7c3eea5b31827e63b35 (6.0-rc5)
 CVE-2023-2877 (The Formidable Forms WordPress plugin before 6.3.1 does not adequately ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-2842 (The WP Inventory Manager WordPress plugin before 2.1.0.14 does not hav ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c50f3b49a07f7c20c323891dc17adf5bd6cf0d4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c50f3b49a07f7c20c323891dc17adf5bd6cf0d4
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230629/d6bdb37c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list