From 62e8c058e38f5ff4d5d5165af4d91f22b8f2dbbe Mon Sep 17 00:00:00 2001 From: Ben Hutchings Date: Tue, 21 Jun 2022 00:05:27 +0200 Subject: Correct break/fix commits for CVE-2022-20148 --- active/CVE-2022-20148 | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/active/CVE-2022-20148 b/active/CVE-2022-20148 index 25bd7ec7..437ccdb2 100644 --- a/active/CVE-2022-20148 +++ b/active/CVE-2022-20148 @@ -1,13 +1,16 @@ -Description: +Description: f2fs: fix UAF in f2fs_available_free_memory References: https://source.android.com/security/bulletin/pixel/2022-06-01 Notes: + bwh> Actually introduced in 5.13, not fixed, by the first + bwh> referenced commit d6d2b491a82e "f2fs: allow to change discard + bwh> policy based on cached discard cmds". Bugs: -upstream: released (5.13-rc1) [d6d2b491a82e1e411a6766fbfb87c697d8701554], released (5.16-rc1) [5429c9dbc9025f9a166f64e22e3a69c94fd5b29b] -5.10-upstream-stable: -4.19-upstream-stable: -4.9-upstream-stable: +upstream: released (5.16-rc1) [5429c9dbc9025f9a166f64e22e3a69c94fd5b29b] +5.10-upstream-stable: N/A "Vulnerability introduced later" +4.19-upstream-stable: N/A "Vulnerability introduced later" +4.9-upstream-stable: N/A "Vulnerability introduced later" sid: released (5.15.3-1) -5.10-bullseye-security: -4.19-buster-security: -4.9-stretch-security: +5.10-bullseye-security: N/A "Vulnerability introduced later" +4.19-buster-security: N/A "Vulnerability introduced later" +4.9-stretch-security: N/A "Vulnerability introduced later" -- cgit v1.2.3