Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #81902 > unrolled thread
| Started by | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| First post | 2024-02-18 20:50 +0100 |
| Last post | 2024-07-15 22:50 +0200 |
| Articles | 4 — 2 participants |
Back to article view | Back to linux.debian.kernel
Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 Salvatore Bonaccorso <carnil@debian.org> - 2024-02-18 20:50 +0100
Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 Salvatore Bonaccorso <carnil@debian.org> - 2024-06-30 21:00 +0200
Processed: Re: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-06-30 21:00 +0200
Bug#1064229: marked as done (firmware-nonfree: CVE-2023-35061) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-07-15 22:50 +0200
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2024-02-18 20:50 +0100 |
| Subject | Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 |
| Message-ID | <I8VkJ-b2G9-1@gated-at.bofh.it> |
Source: firmware-nonfree
Version: 20230625-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Hi,
The following vulnerabilities were published for firmware-nonfree.
They are addressed in the linux-firmware/20231211 upstream version.
CVE-2023-35061[0]:
| Improper initialization for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable information disclosure
| via adjacent access.
CVE-2023-34983[1]:
| Improper input validation for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access.
CVE-2023-33875[2]:
| Improper access control for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| local access..
CVE-2023-32651[3]:
| Improper validation of specified type of input for some Intel(R)
| PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before
| version 22.240 may allow an unauthenticated user to potentially
| enable denial of service via adjacent access.
CVE-2023-32644[4]:
| Protection mechanism failure for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access.
CVE-2023-32642[5]:
| Insufficient adherence to expected conventions for some Intel(R)
| PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before
| version 22.240 may allow an unauthenticated user to potentially
| enable denial of service via adjacent access.
CVE-2023-28720[6]:
| Improper initialization for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access..
CVE-2023-28374[7]:
| Improper input validation for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access.
CVE-2023-26586[8]:
| Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R)
| Killer(TM) Wi-Fi software before version 22.240 may allow an
| unauthenticated user to potentially enable denial of service via
| adjacent access.
CVE-2023-25951[9]:
| Improper input validation for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a
| privileged user to potentially enable escalation of privilege via
| local access.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2023-35061
https://www.cve.org/CVERecord?id=CVE-2023-35061
[1] https://security-tracker.debian.org/tracker/CVE-2023-34983
https://www.cve.org/CVERecord?id=CVE-2023-34983
[2] https://security-tracker.debian.org/tracker/CVE-2023-33875
https://www.cve.org/CVERecord?id=CVE-2023-33875
[3] https://security-tracker.debian.org/tracker/CVE-2023-32651
https://www.cve.org/CVERecord?id=CVE-2023-32651
[4] https://security-tracker.debian.org/tracker/CVE-2023-32644
https://www.cve.org/CVERecord?id=CVE-2023-32644
[5] https://security-tracker.debian.org/tracker/CVE-2023-32642
https://www.cve.org/CVERecord?id=CVE-2023-32642
[6] https://security-tracker.debian.org/tracker/CVE-2023-28720
https://www.cve.org/CVERecord?id=CVE-2023-28720
[7] https://security-tracker.debian.org/tracker/CVE-2023-28374
https://www.cve.org/CVERecord?id=CVE-2023-28374
[8] https://security-tracker.debian.org/tracker/CVE-2023-26586
https://www.cve.org/CVERecord?id=CVE-2023-26586
[9] https://security-tracker.debian.org/tracker/CVE-2023-25951
https://www.cve.org/CVERecord?id=CVE-2023-25951
Regards,
Salvatore
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2024-06-30 21:00 +0200 |
| Message-ID | <IV7Wh-6K5l-3@gated-at.bofh.it> |
| In reply to | #81902 |
Control: retitle -1 firmware-nonfree: CVE-2023-35061 Hi Ben, On Sun, Jun 30, 2024 at 08:42:32PM +0200, Ben Hutchings wrote: > On Sun, 18 Feb 2024 20:45:07 +0100 Salvatore Bonaccorso > <carnil@debian.org> wrote: > > Source: firmware-nonfree > > Version: 20230625-2 > > Severity: important > > Tags: security upstream > > X-Debbugs-Cc: carnil@debian.org, Debian Security Team > <team@security.debian.org> > > > > Hi, > > > > The following vulnerabilities were published for firmware-nonfree. > > > > They are addressed in the linux-firmware/20231211 upstream version. > [...] > > According to > <https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html> > only CVE-2023-35061 affects Linux (presumably the other issues are in > the Windows driver, not the firmware). You are right. I'm not sure if that information was already availablewhen filling the bug, bug surely I will now fix the tracker information then to only reflect it for CVE-2023-35061. Thanks for the headsup! Salvatore
[toc] | [prev] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2024-06-30 21:00 +0200 |
| Subject | Processed: Re: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 |
| Message-ID | <IV7Wi-6K5l-7@gated-at.bofh.it> |
| In reply to | #81902 |
Processing control commands: > retitle -1 firmware-nonfree: CVE-2023-35061 Bug #1064229 [src:firmware-nonfree] firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 Changed Bug title to 'firmware-nonfree: CVE-2023-35061' from 'firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951'. -- 1064229: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064229 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2024-07-15 22:50 +0200 |
| Subject | Bug#1064229: marked as done (firmware-nonfree: CVE-2023-35061) |
| Message-ID | <J0ANX-2ntD-5@gated-at.bofh.it> |
| In reply to | #81902 |
[Multipart message — attachments visible in raw view] — view raw
Your message dated Mon, 15 Jul 2024 20:45:46 +0000 with message-id <E1sTSZu-00DUy8-Gi@fasolo.debian.org> and subject line Bug#1064229: fixed in firmware-nonfree 20240610-1 has caused the Debian Bug report #1064229, regarding firmware-nonfree: CVE-2023-35061 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 1064229: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064229 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web