Re: New CVE entry this week
Masami Ichikawa
Hi !
On Thu, Sep 2, 2021 at 3:28 PM Pavel Machek <pavel@...> wrote:
This weekly report mail contains full list which are new CVEs, updated
CVEs, and currently tracking CVEs, so summary can be removed or make
it simple I think.
I'll write a new summary style that includes CVEs which we need to take care of.
--
Masami Ichikawa
Cybertrust Japan Co., Ltd.
Email :masami.ichikawa@...
:masami.ichikawa@...
On Thu, Sep 2, 2021 at 3:28 PM Pavel Machek <pavel@...> wrote:
Thank you for the comment.
Hi!* CVE short summaryThese summaries are not so short; I simply skip them and go to full
list. Perhaps they don't need to be included, or could include only
CVEs where we need to take an action?
This weekly report mail contains full list which are new CVEs, updated
CVEs, and currently tracking CVEs, so summary can be removed or make
it simple I think.
I'll write a new summary style that includes CVEs which we need to take care of.
Regards,* CVE detailThis one is queued for 5.10.62, so this is getting fixed for us.
New CVEs
CVE-2021-3739: btrfs: fix NULL pointer dereference when deleting
device by invalid id
Fixed in btrfs tree but not fixed in mainline yet.
This vulnerability has been introduced since 4.20-rc1 so before 4.20
kernel aren't affected this vulnerability.
Fixed status
mainline: [e4571b8c5e9ffa1e85c0c671995bd4dcc5c75091]CVE-2021-3743: out-of-bound Read in qrtr_endpoint_post in net/qrtr/qrtr.cFixes are queued for 4.19 and 5.10.62, so this is getting fixed for us.
The Qualcomm's IPC router protocol(qrtr) has been introduced since
4.15-rc1 so before 4.15 kernels aren't affected.
Checked on cip-kernel-config, it looks like no CIP member enables QRTR.
Fixed status
mainline: [7e78c597c3ebfd0cb329aa09a838734147e4f117]CVE-2021-3753: A out-of-bounds caused by the race of KDSETMODE in vtAgreed, fixed in 4.19.192 and 4.4.270. Nothing for us to do there.
Commit ffb324e6f874121f7dce5bdae5e05d02baae7269 introduced race
condition and oob bug. The commit ffb324e6f874 have been backported to
4.4 and 4.19.Updated CVEsFixed in 4.14 but not 4.4.
CVE-2020-3702: Specifically timed and handcrafted traffic can cause
internal errors in a WLAN device that lead to improper layer 2 Wi-Fi
encryption with a consequent possibility of information disclosure
over the air for a discrete set of traffic
Vulnerability in ath9k driver. 4.4.y-cip/arm/siemens_imx6_defconfig
and 4.4.y-cip/arm/moxa_mxc_defconfig use ath9k.stable/4.14: [2cbb22fd4b4fb4d0822d185bf5bd6d027107bfda,Diffstat looks like this:
20e7de09cbdb76a38f28fb71709fae347123ddb7,
995586a56748c532850870523d3a9080492b3433,
f4d4f4473129e9ee55b8562250adc53217bad529,
61b014a8f8de02bedc56f76620170437f5638588]
key.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
main.c | 5 +++++
1 file changed, 5 insertions(+)
ath.h | 1 +
key.c | 4 ++--
2 files changed, 3 insertions(+), 2 deletions(-)
ath.h | 2 +-
ath5k/mac80211-ops.c | 2 +-
ath9k/htc_drv_main.c | 2 +-
ath9k/main.c | 5 ++---
key.c | 34 +++++++++++++++++-----------------
5 files changed, 22 insertions(+), 23 deletions(-)
hw.h | 1
main.c | 87 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-
2 files changed, 87 insertions(+), 1 deletion(-)
Best regards,
Pavel
--
DENX Software Engineering GmbH, Managing Director: Wolfgang Denk
HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
--
Masami Ichikawa
Cybertrust Japan Co., Ltd.
Email :masami.ichikawa@...
:masami.ichikawa@...