Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20200610114427.GA1895802@kroah.com>
Date: Wed, 10 Jun 2020 13:44:27 +0200
From: Greg KH <gregkh@...uxfoundation.org>
To: oss-security@...ts.openwall.com
Subject: Re: kernel: Multiple SSBD related flaws
 CVE-2020-10766 , CVE-2020-10767, CVE-2020-10768

On Wed, Jun 10, 2020 at 09:21:03PM +1000, Wade Mealing wrote:
> A number of flaws were discussed in the registers article this morning
> ( https://www.theregister.com/2020/06/09/linux_kernel_bugs_spectre )
> which have been submitted for inclusion upstream already.
> 
> Listed below are the CVE's that Red Hat has assigned.  As far as I can
> tell there are no existing  CVE assignments for these flaws. I have
> not done adequate investigation to correctly identify affected
> versions of the kernel, however this is a flaw in the fix for
> CVE-2018-3639, affected systems would likely be affected by the flaws
> listed below if they required the fix.

Did you ask the authors of the patches?  I think they might have already
assigned CVEs from Google's pool, based on previous interactions with
those developers...

thanks,

greg k-h

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.