|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2023-3108: kernel-source-azure,kernel-source,kernel-source-rt: race condition in crypto module in the function skcipher_recvmsg | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Thomas Leroy <thomas.leroy> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED UPSTREAM | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | chester.lin, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/371773/ | ||
| Whiteboard: | |||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Thomas Leroy
2023-07-11 06:12:47 UTC
Both fixing and buggy commits were introduced in v4.0-rc1. I don't really know why a CVE is assigned now. Since both commits were introduced in the same version, our branches containing the buggy commit also have the fixing one. Leaving open to add the CVE id in the changelogs: - SLE15-SP4 - cve/linux-4.12 - cve/linux-4.4 - cve/linux-5.3 - stable (In reply to Thomas Leroy from comment #1) > Both fixing and buggy commits were introduced in v4.0-rc1. I don't really > know why a CVE is assigned now. > > Since both commits were introduced in the same version, our branches > containing the buggy commit also have the fixing one. Leaving open to add > the CVE id in the changelogs: > > - SLE15-SP4 > - cve/linux-4.12 > - cve/linux-4.4 > - cve/linux-5.3 > - stable Looks like we don't need to backport this patch since it has been included in the upstream kernel bases we selected, which means no kernel patch metadata needs to be revised for this CVE. Not sure if anything the kernel team can help with so reassign this CVE back to the security team, thanks. |