Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 77e391a1 by Salvatore Bonaccorso at 2024-11-16T11:24:26+01:00 Update Intel CVEs related to INTEL-SA-01108 - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -747,7 +747,16 @@ CVE-2024-28051 (Out-of-bounds read in some Intel(R) VPL software before version [bookworm] - onevpl-intel-gpu <ignored> (Minor issue) NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01131.html CVE-2024-28049 (Improper input validation in firmware for some Intel(R) PROSet/Wireles ...) - TODO: check + - firmware-nonfree 20240610-1 + [bookworm] - firmware-nonfree <ignored> (Minor issue; upstream commits not fully confirmed by Intel) + NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01108.html + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=0c0898b4e0a4c1a46ae01fb42bf39f1cb0dab770 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=b3d445a98ebd6779d921a152349844c3e7b86bf8 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=02ad85a367efdac04e2a33d4f287b689906cb2cd + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2986e19030e01d9032a62f488e610a210d30ce0b + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=ded56705e80b1f5ad10650cd9196717ba71cbe17 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2f1461dd48dedd2f3704860e2c045625bbb43a3a + NOTE: In referenced commits firmware get updated fo release version at last 23.40.0.2. CVE-2024-28030 (NULL pointer dereference in some Intel(R) VPL software before version ...) - intel-mediasdk <removed> [bookworm] - intel-mediasdk <ignored> (No specific details published, development stalled and scheduled for removal from Debian) @@ -765,11 +774,29 @@ CVE-2024-25647 (Incorrect default permissions for some Intel(R) Binary Configura CVE-2024-25565 (Insufficient control flow management in UEFI firmware for some Intel(R ...) NOT-FOR-US: Intel CVE-2024-25563 (Improper initialization in firmware for some Intel(R) PROSet/Wireless ...) - TODO: check + - firmware-nonfree 20240610-1 + [bookworm] - firmware-nonfree <ignored> (Minor issue; upstream commits not fully confirmed by Intel) + NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01108.html + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=0c0898b4e0a4c1a46ae01fb42bf39f1cb0dab770 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=b3d445a98ebd6779d921a152349844c3e7b86bf8 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=02ad85a367efdac04e2a33d4f287b689906cb2cd + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2986e19030e01d9032a62f488e610a210d30ce0b + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=ded56705e80b1f5ad10650cd9196717ba71cbe17 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2f1461dd48dedd2f3704860e2c045625bbb43a3a + NOTE: In referenced commits firmware get updated fo release version at last 23.40.0.2. CVE-2024-24985 (Exposure of resource to wrong sphere in some Intel(R) processors with ...) NOT-FOR-US: Intel CVE-2024-24984 (Improper input validation for some Intel(R) Wireless Bluetooth(R) prod ...) - TODO: check + - firmware-nonfree 20240610-1 + [bookworm] - firmware-nonfree <ignored> (Minor issue; upstream commits not fully confirmed by Intel) + NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01108.html + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=0c0898b4e0a4c1a46ae01fb42bf39f1cb0dab770 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=b3d445a98ebd6779d921a152349844c3e7b86bf8 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=02ad85a367efdac04e2a33d4f287b689906cb2cd + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2986e19030e01d9032a62f488e610a210d30ce0b + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=ded56705e80b1f5ad10650cd9196717ba71cbe17 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2f1461dd48dedd2f3704860e2c045625bbb43a3a + NOTE: In referenced commits firmware get updated fo release version at last 23.40.0.2. CVE-2024-23919 (Improper buffer restrictions in some Intel(R) Graphics software may al ...) NOT-FOR-US: Intel CVE-2024-23918 (Improper conditions check in some Intel(R) Xeon(R) processor memory co ...) @@ -779,7 +806,16 @@ CVE-2024-23918 (Improper conditions check in some Intel(R) Xeon(R) processor mem CVE-2024-23312 (Uncontrolled search path for some Intel(R) Binary Configuration Tool s ...) NOT-FOR-US: Intel CVE-2024-23198 (Improper input validation in firmware for some Intel(R) PROSet/Wireles ...) - TODO: check + - firmware-nonfree 20240610-1 + [bookworm] - firmware-nonfree <ignored> (Minor issue; upstream commits not fully confirmed by Intel) + NOTE: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01108.html + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=0c0898b4e0a4c1a46ae01fb42bf39f1cb0dab770 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=b3d445a98ebd6779d921a152349844c3e7b86bf8 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=02ad85a367efdac04e2a33d4f287b689906cb2cd + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2986e19030e01d9032a62f488e610a210d30ce0b + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=ded56705e80b1f5ad10650cd9196717ba71cbe17 + NOTE: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=2f1461dd48dedd2f3704860e2c045625bbb43a3a + NOTE: In referenced commits firmware get updated fo release version at last 23.40.0.2. CVE-2024-22185 (Time-of-check Time-of-use Race Condition in some Intel(R) processors w ...) NOT-FOR-US: Intel CVE-2024-21853 (Improper finite state machines (FSMs) in the hardware logic in some 4t ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/77e391a1376b22a32f990c07c198d605c8997ac0 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/77e391a1376b22a32f990c07c198d605c8997ac0 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits