Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
fd1f2574 by Salvatore Bonaccorso at 2020-12-09T22:37:14+01:00
Add todo item for CVE-2020-3702

It is not very clear if the very same CVE would then be used, but it was
asked to reconsider the entry as
https://lore.kernel.org/linux-wireless/CABvG-CVvPF++0vuGzCrBj8+s=bcx1gwwfiw1_somu_gvnct...@mail.gmail.com/
is refering to it and mentioning issues on the Linux kernel side.

Needs some further investigation.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -66930,6 +66930,7 @@ CVE-2020-3704 (u'While processing invalid connection 
request PDU which is nonsta
 CVE-2020-3703 (u'Buffer over-read issue in Bluetooth peripheral firmware due 
to lack  ...)
        NOT-FOR-US: Qualcomm components for Android
 CVE-2020-3702 (u'Specifically timed and handcrafted traffic can cause internal 
errors ...)
+       TODO: check, it might affect src:linux as pointed out in 
https://lore.kernel.org/linux-wireless/CABvG-CVvPF++0vuGzCrBj8+s=bcx1gwwfiw1_somu_gvnct...@mail.gmail.com/
        NOT-FOR-US: Snapdragon
 CVE-2020-3701 (Use after free issue while processing error notification from 
camx dri ...)
        NOT-FOR-US: Qualcomm components for Android



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd1f2574a77b8af08d6ff8aad394c3b29cd507bf

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fd1f2574a77b8af08d6ff8aad394c3b29cd507bf
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to