Tobias Frost pushed to branch master at Debian Security Tracker / security-tracker
Commits: 19b117a2 by Tobias Frost at 2024-02-09T20:25:59+01:00 Document progress on nss: NOTE: 20240209: Tried to backport patches for CVE-2023-6135, however it is unclear which bits are required or if the NOTE: 20240209: fix would be to backport nss to utilize HACL*. The version in buster does not have the NIST ciphers NOTE: 20240209: in the files touched by the upstream patch. TL;DR: I'm unsure if the prepared patches are fixing the vulnerabilty. NOTE: 20240209: The backported patches are in the LTS repository, CVE-2023-6135*.patch </tobi> - - - - - 1 changed file: - data/dla-needed.txt Changes: ===================================== data/dla-needed.txt ===================================== @@ -165,6 +165,11 @@ nova -- nss (tobi) NOTE: 20240121: Added by Front-Desk (apo) + NOTE: 20240209: <tobi> There is currently no (public) patch for CVE-2023-5388 - RedHat seems to have one in privateā¦ (tobi) + NOTE: 20240209: Tried to backport patches for CVE-2023-6135, however it is unclear which bits are required or if the + NOTE: 20240209: fix would be to backport nss to utilize HACL*. The version in buster does not have the NIST ciphers + NOTE: 20240209: in the files touched by the upstream patch. TL;DR: I'm unsure if the prepared patches are fixing the vulnerabilty. + NOTE: 20240209: The backported patches are in the LTS repository, CVE-2023-6135*.patch </tobi> -- nvidia-cuda-toolkit NOTE: 20230514: Added by Front-Desk (utkarsh) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19b117a202dea1a2def53936ef1b42a498c46f84 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/19b117a202dea1a2def53936ef1b42a498c46f84 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits