[Git][security-tracker-team/security-tracker][master] Add CVE-2023-39194/linux

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Oct 5 08:22:02 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0622be26 by Salvatore Bonaccorso at 2023-10-05T09:19:30+02:00
Add CVE-2023-39194/linux

- - - - -


2 changed files:

- data/CVE/list
- data/next-oldstable-point-update.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -86,6 +86,11 @@ CVE-2023-3038 (SQL injection vulnerability in HelpDezk Community affecting versi
 	TODO: check
 CVE-2023-3037 (Improper authorization vulnerability in HelpDezk Community affecting v ...)
 	TODO: check
+CVE-2023-39194 [net: xfrm: Fix xfrm_address_filter OOB read]
+	- linux 6.4.13-1
+	[bookworm] - linux 6.1.52-1
+	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1492/
+	NOTE: https://git.kernel.org/linus/dfa73c17d55b921e1d4e154976de35317e43a93a (6.5-rc7)
 CVE-2023-39193 [netfilter: xt_sctp: validate the flag_info count]
 	- linux 6.5.3-1
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-23-1491/


=====================================
data/next-oldstable-point-update.txt
=====================================
@@ -228,6 +228,8 @@ CVE-2023-44469
 	[bullseye] - lemonldap-ng 2.0.11+ds-4+deb11u5
 CVE-2021-38185
 	[bullseye] - cpio 2.13+dfsg-7.1~deb11u1
+CVE-2023-39194
+	[bullseye] - linux 5.10.197-1
 CVE-2023-39193
 	[bullseye] - linux 5.10.197-1
 CVE-2023-39192



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0622be262b3e65489ce4a55a308419bf1659d4c8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0622be262b3e65489ce4a55a308419bf1659d4c8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231005/5a4f00fe/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list