[Git][security-tracker-team/security-tracker][master] CVE-2023-4244 got preferred instread of CVE-2023-4563

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 14 21:23:15 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2ff39f80 by Salvatore Bonaccorso at 2023-09-14T22:21:57+02:00
CVE-2023-4244 got preferred instread of CVE-2023-4563

Rewrite CVE entries to get the information under the Google CNA assigned
CVE, whereas the Red Hat assigned CVE got REJECTED.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -952,7 +952,10 @@ CVE-2023-4588 (File accessibility vulnerability in Delinea Secret Server, in its
 CVE-2023-4498 (Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access ...)
 	NOT-FOR-US: Tenda
 CVE-2023-4244 (A use-after-free vulnerability in the Linux kernel's netfilter: nf_tab ...)
-	NOTE: Duplicate of CVE-2023-4563 (RedHat assigned)
+	- linux 6.4.13-1
+	NOTE: https://lore.kernel.org/netdev/20230810070830.24064-1-pablo@netfilter.org/
+	NOTE: https://lore.kernel.org/netdev/20230815223011.7019-1-fw@strlen.de/
+	NOTE: https://kernel.dance/3e91b0ebd994635df2346353322ac51ce84ce6d8
 CVE-2023-4208 (A use-after-free vulnerability in the Linux kernel's net/sched: cls_u3 ...)
 	{DSA-5492-1}
 	- linux 6.4.11-1
@@ -2597,11 +2600,8 @@ CVE-2023-4567
 	[bookworm] - ansible <no-dsa> (Minor issue)
 	[bullseye] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2235369
-CVE-2023-4563 [Use-after-free in nft_verdict_dump due to a race between set GC and transaction]
+CVE-2023-4563
 	REJECTED
-	- linux 6.4.13-1
-	NOTE: https://lore.kernel.org/netdev/20230810070830.24064-1-pablo@netfilter.org/
-	NOTE: https://lore.kernel.org/netdev/20230815223011.7019-1-fw@strlen.de/
 CVE-2023-41109 (SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Com ...)
 	NOT-FOR-US: SmartNode SN200 (aka SN200)
 CVE-2023-40846 (Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Bu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ff39f80ac440b8e4a5163bd319d9fa06d78393c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ff39f80ac440b8e4a5163bd319d9fa06d78393c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230914/025c3435/attachment.htm>


More information about the debian-security-tracker-commits mailing list