[Git][security-tracker-team/security-tracker][master] Reserve DLA-4137-1 for libbpf

Adrian Bunk (@bunk) bunk at debian.org
Thu Apr 24 18:39:40 BST 2025



Adrian Bunk pushed to branch master at Debian Security Tracker / security-tracker


Commits:
23227e36 by Adrian Bunk at 2025-04-24T20:39:27+03:00
Reserve DLA-4137-1 for libbpf

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -220965,7 +220965,6 @@ CVE-2022-3607 (Failure to Sanitize Special Elements into a Different Plane (Spec
 	- octoprint <itp> (bug #718591)
 CVE-2022-3606 (A vulnerability was found in Linux Kernel. It has been classified as p ...)
 	- libbpf 1.1.0-1 (bug #1023717)
-	[bullseye] - libbpf <no-dsa> (Minor issue)
 	NOTE: Introduced by: https://github.com/libbpf/libbpf/commit/a3abae5122f30b83baebd4e4dd8ba4578a87cd4b (v0.2)
 	NOTE: Fixed by: https://github.com/libbpf/libbpf/commit/3a3ef0c1d09e1894740db71cdcb7be0bfd713671 (v1.1.0)
 CVE-2022-3605 (The WP CSV Exporter WordPress plugin before 1.3.7 does not properly es ...)
@@ -222239,7 +222238,6 @@ CVE-2022-3535
 	REJECTED
 CVE-2022-3534 (A vulnerability classified as critical has been found in Linux Kernel. ...)
 	- libbpf 1.1.0-1 (bug #1023717)
-	[bullseye] - libbpf <no-dsa> (Minor issue)
 	NOTE: Introduced by: https://github.com/libbpf/libbpf/commit/7ac1547f32f060d84b06c74edbb2c6896cc07949 (v0.2)
 	NOTE: Fixed by: https://github.com/libbpf/libbpf/commit/54caf920db0e489de90f3aaaa41e2a51ddbcd084 (v1.1.0)
 CVE-2022-3533 (A vulnerability was found in Linux Kernel. It has been rated as proble ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[24 Apr 2025] DLA-4137-1 libbpf - security update
+	{CVE-2022-3534 CVE-2022-3606}
+	[bullseye] - libbpf 0.3-2+deb11u1
 [24 Apr 2025] DLA-4136-1 openrazer - security update
 	{CVE-2022-23467 CVE-2022-29021 CVE-2022-29022 CVE-2022-29023 CVE-2025-32776}
 	[bullseye] - openrazer 2.9.0+dfsg-1+deb11u1


=====================================
data/dla-needed.txt
=====================================
@@ -149,9 +149,6 @@ krb5
   NOTE: 20250422: Added by Front-Desk (rouca)
   NOTE: 20250422: Backporting knob allow_des3 and allow_rc4 variables in [libdefaults] may be suffisant (rouca)
 --
-libbpf (Adrian Bunk)
-  NOTE: 20250422: Added by Front-Desk (rouca)
---
 libbson-xs-perl (roberto)
   NOTE: 20250331: Added by Front-Desk (Beuc)
   NOTE: 20250331: Cf. mongo-c-driver (provides libbson which libbson-xs-perl embeds) (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/23227e36a66bac34b5c317b5520f919f91dd3c5a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/23227e36a66bac34b5c317b5520f919f91dd3c5a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250424/33be2094/attachment.htm>


More information about the debian-security-tracker-commits mailing list