From c48f03ca729e3f847485f5e7581103d5f4d64d01 Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Thu, 20 Jan 2022 16:25:42 +0100 Subject: follow sec team and mark some CVEs of glibc as no-dsa --- data/CVE/2021.list | 2 ++ data/CVE/2022.list | 2 ++ 2 files changed, 4 insertions(+) diff --git a/data/CVE/2021.list b/data/CVE/2021.list index aa131c5ff1..a0164e4e98 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -6022,12 +6022,14 @@ CVE-2021-3999 [Off-by-one buffer overflow/underflow in getcwd()] - glibc [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=28769 CVE-2021-3998 [Unexpected return value from realpath() for too long results] RESERVED - glibc [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=28770 NOTE: https://patchwork.sourceware.org/project/glibc/patch/20220113055920.3155918-1-siddhesh@sourceware.org/ CVE-2021-3997 [Uncontrolled recursion in systemd's systemd-tmpfiles] diff --git a/data/CVE/2022.list b/data/CVE/2022.list index ec40d5ca0d..fc6847329a 100644 --- a/data/CVE/2022.list +++ b/data/CVE/2022.list @@ -1383,11 +1383,13 @@ CVE-2022-23219 (The deprecated compatibility function clnt_create in the sunrpc - glibc 2.33-3 [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=22542 CVE-2022-23218 (The deprecated compatibility function svcunix_create in the sunrpc mod ...) - glibc 2.33-3 [bullseye] - glibc (Minor issue) [buster] - glibc (Minor issue) + [stretch] - glibc (Minor issue) NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=28768 CVE-2022-23217 RESERVED -- cgit v1.2.3