From 7661511d0dde1672e2c554637e6a313c936e0688 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Wed, 17 Jan 2024 21:17:59 +0100 Subject: Retire some CVEs --- retired/CVE-2024-0582 | 16 ++++++++++++++++ retired/CVE-2024-0584 | 14 ++++++++++++++ 2 files changed, 30 insertions(+) create mode 100644 retired/CVE-2024-0582 create mode 100644 retired/CVE-2024-0584 (limited to 'retired') diff --git a/retired/CVE-2024-0582 b/retired/CVE-2024-0582 new file mode 100644 index 00000000..d1be9f88 --- /dev/null +++ b/retired/CVE-2024-0582 @@ -0,0 +1,16 @@ +Description: io_uring/kbuf: defer release of mapped buffer rings +References: + https://bugs.chromium.org/p/project-zero/issues/detail?id=2504 + https://bugzilla.redhat.com/show_bug.cgi?id=2254050 +Notes: + carnil> Issue introduced with c56e022c0a27 ("io_uring: add support for + carnil> user mapped provided buffer ring") in 6.4-rc1. +Bugs: +upstream: released (6.7-rc4) [c392cbecd8eca4c53f2bf508731257d9d0a21c2d] +6.1-upstream-stable: N/A "Vulnerable code not present" +5.10-upstream-stable: N/A "Vulnerable code not present" +4.19-upstream-stable: N/A "Vulnerable code not present" +sid: released (6.6.8-1) +6.1-bookworm-security: N/A "Vulnerable code not present" +5.10-bullseye-security: N/A "Vulnerable code not present" +4.19-buster-security: N/A "Vulnerable code not present" diff --git a/retired/CVE-2024-0584 b/retired/CVE-2024-0584 new file mode 100644 index 00000000..d7ce039b --- /dev/null +++ b/retired/CVE-2024-0584 @@ -0,0 +1,14 @@ +Description: ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet +References: + https://bugzilla.redhat.com/show_bug.cgi?id=2258584 + https://lore.kernel.org/netdev/170083982540.9628.4546899811301303734.git-patchwork-notify@kernel.org/T/ +Notes: +Bugs: +upstream: released (6.7-rc4) [e2b706c691905fe78468c361aaabc719d0a496f1] +6.1-upstream-stable: released (6.1.66) [94445d9583079e0ccc5dde1370076ff24800d86e] +5.10-upstream-stable: released (5.10.203) [772fe1da9a8d4dcd8993abaecbde04789c52a4c2] +4.19-upstream-stable: released (4.19.301) [6b6f5c6671fdfde9c94efe6409fa9f39436017e7] +sid: released (6.6.8-1) +6.1-bookworm-security: released (6.1.66-1) +5.10-bullseye-security: released (5.10.205-1) +4.19-buster-security: released (4.19.304-1) -- cgit v1.2.3