From 218fe42888bafa54c069f928f9fe23a716db8077 Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Mon, 3 Jan 2022 16:01:43 +0100 Subject: new rust-nix, rust-tokio issues --- data/CVE/2021.list | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/data/CVE/2021.list b/data/CVE/2021.list index df6518abab..21e3739376 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -704,13 +704,19 @@ CVE-2021-45712 (An issue was discovered in the rust-embed crate before 6.3.0 for CVE-2021-45711 (An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 fo ...) NOT-FOR-US: Rust crate simple_asn1 CVE-2021-45710 (An issue was discovered in the tokio crate before 1.8.4, and 1.9.x thr ...) - TODO: check + - rust-tokio + [bullseye] - rust-tokio (Minor issue) + NOTE: https://rustsec.org/advisories/RUSTSEC-2021-0124.html + NOTE: https://github.com/tokio-rs/tokio/issues/4225 CVE-2021-45709 (An issue was discovered in the crypto2 crate through 2021-10-08 for Ru ...) NOT-FOR-US: Rust crate crypto2 CVE-2021-45708 (An issue was discovered in the abomonation crate through 2021-10-17 fo ...) NOT-FOR-US: Rust crate abomonation CVE-2021-45707 (An issue was discovered in the nix crate before 0.20.2, 0.21.x before ...) - TODO: check + - rust-nix 0.23.0-1 + [bullseye] - rust-nix (Minor issue) + [buster] - rust-nix (Introduced in 0.16) + NOTE: https://rustsec.org/advisories/RUSTSEC-2021-0119.html CVE-2021-45706 (An issue was discovered in the zeroize_derive crate before 1.1.1 for R ...) NOT-FOR-US: Rust crate zeroize_derive CVE-2021-45705 (An issue was discovered in the nanorand crate before 0.6.1 for Rust. T ...) -- cgit v1.2.3