[SRU] [T/X/B/C/D] [PATCH 0/1] CVE-2019-3460 - Heap data infoleak in multiple locations including functionl2cap_parse_conf_rsp

Tyler Hicks tyhicks at canonical.com
Tue Feb 19 16:39:53 UTC 2019


On 2019-02-19 20:27:43, Kai-Heng Feng wrote:
> For Trusty, another commit is cherry-picked as an dependency. The commit
> has a CVE number, but somehow it's not in the CVE Matrix.

The problem was that the ubuntu-cve-tracker had the wrong information
about the commit that fixed the this CVE. I've adjusted the
ubuntu-cve-tracker and now it correctly shows that Trusty has not
received this CVE fix. Thanks for pointing this out!

Tyler
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20190219/47a69d91/attachment.sig>


More information about the kernel-team mailing list