Re: pluxml issues are questionable, request for advice

2020-12-16 Thread Adrian Bunk
On Wed, Dec 16, 2020 at 07:36:19AM +0100, Ola Lundqvist wrote: > Hi LTS team > > I have checked two of the pluxml issues > CVE-2020-18184 > This vulnerability is questioned upstream. >... > The question is how this should be marked: > - no-dsa minor issue? > - ignored? >... "not a vulnerability"

Re: pluxml issues are questionable, request for advice

2020-12-16 Thread Moritz Mühlenhoff
On Wed, Dec 16, 2020 at 10:28:47AM +0200, Adrian Bunk wrote: > On Wed, Dec 16, 2020 at 07:36:19AM +0100, Ola Lundqvist wrote: > > Hi LTS team > > > > I have checked two of the pluxml issues > > CVE-2020-18184 > > This vulnerability is questioned upstream. > >... > > The question is how this shoul

Re: [SECURITY] [DLA 2483-1] linux-4.19 security update

2020-12-16 Thread Robert Doran
Removed: linux-headers-4.19-686-pae 4.19+105+deb10u7~deb9u1 linux-headers-4.19-amd64 4.19+105+deb10u7~deb9u1 linux-headers-4.19-cloud-amd64 4.19+105+deb10u7~deb9u1 linux-image-4.19-686-pae 4.19+105+deb10u7~deb9u1 linux-image-4.19-amd64 4.19+105+deb10u7~deb9u1 linux-image-4.19-clou

Re: pluxml issues are questionable, request for advice

2020-12-16 Thread Ola Lundqvist
severity 973382 normal thanks Hi Moritz and Adrian Thank you for the advice. I have now marked these two CVEs as unimportant. I have also downgraded the bug (with this email). If someone does not agree, it is easy to revert my actions. Cheers // Ola On Wed, 16 Dec 2020 at 13:58, Moritz Mühlen