summaryrefslogtreecommitdiffstats
path: root/active/CVE-2023-52616
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2024-03-18 18:04:48 +0100
committerSalvatore Bonaccorso <carnil@debian.org>2024-03-18 18:04:48 +0100
commitbcd9eccef0863578591f91cfde157a7c1fcf4d9e (patch)
tree51bcfe848aef821a7b1a16ad6c272fc86e25630e /active/CVE-2023-52616
parent602dff7a3e25bb7b7271a9400d5ff4ce861d05c0 (diff)
Add new batch of CVEs
Fixup for fix in earlier versions as 6.6.15-1 and one N/A as vulnerable code was only introduced in 6.7 series.
Diffstat (limited to 'active/CVE-2023-52616')
-rw-r--r--active/CVE-2023-5261616
1 files changed, 16 insertions, 0 deletions
diff --git a/active/CVE-2023-52616 b/active/CVE-2023-52616
new file mode 100644
index 000000000..2cf3a418a
--- /dev/null
+++ b/active/CVE-2023-52616
@@ -0,0 +1,16 @@
+Description: crypto: lib/mpi - Fix unexpected pointer access in mpi_ec_init
+References:
+Notes:
+ carnil> Introduced in d58bb7e55a8a ("lib/mpi: Introduce ec implementation to MPI
+ carnil> library"). Vulnerable versions: 5.10-rc1.
+Bugs:
+upstream: released (6.8-rc1) [ba3c5574203034781ac4231acf117da917efcd2a]
+6.7-upstream-stable: released (6.7.3) [7abdfd45a650c714d5ebab564bb1b988f14d9b49]
+6.6-upstream-stable: released (6.6.15) [7ebf812b7019fd2d4d5a7ca45ef4bf3a6f4bda0a]
+6.1-upstream-stable: released (6.1.79) [bb44477d4506e52785693a39f03cdc6a2c5e8598]
+5.10-upstream-stable: released (5.10.210) [0c3687822259a7628c85cd21a3445cbe3c367165]
+4.19-upstream-stable: N/A "Vulnerable code not present"
+sid: released (6.6.15-1)
+6.1-bookworm-security: needed
+5.10-bullseye-security: needed
+4.19-buster-security: N/A "Vulnerable code not present"

© 2014-2024 Faster IT GmbH | imprint | privacy policy