Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #81902 > unrolled thread

Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951

Started bySalvatore Bonaccorso <carnil@debian.org>
First post2024-02-18 20:50 +0100
Last post2024-07-15 22:50 +0200
Articles 4 — 2 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 Salvatore Bonaccorso <carnil@debian.org> - 2024-02-18 20:50 +0100
    Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 Salvatore Bonaccorso <carnil@debian.org> - 2024-06-30 21:00 +0200
    Processed: Re: firmware-nonfree: CVE-2023-35061 CVE-2023-34983  CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720  CVE-2023-28374 CVE-2023-26586 CVE-2023-25951 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-06-30 21:00 +0200
    Bug#1064229: marked as done (firmware-nonfree: CVE-2023-35061) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-07-15 22:50 +0200

#81902 — Bug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-02-18 20:50 +0100
SubjectBug#1064229: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951
Message-ID<I8VkJ-b2G9-1@gated-at.bofh.it>
Source: firmware-nonfree
Version: 20230625-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerabilities were published for firmware-nonfree.

They are addressed in the linux-firmware/20231211 upstream version.

CVE-2023-35061[0]:
| Improper initialization for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable information disclosure
| via adjacent access.


CVE-2023-34983[1]:
| Improper input validation for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access.


CVE-2023-33875[2]:
| Improper access control for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| local access..


CVE-2023-32651[3]:
| Improper validation of specified type of input for some Intel(R)
| PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before
| version 22.240 may allow an unauthenticated user to potentially
| enable denial of service via adjacent access.


CVE-2023-32644[4]:
| Protection mechanism failure for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access.


CVE-2023-32642[5]:
| Insufficient adherence to expected conventions for some Intel(R)
| PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before
| version 22.240 may allow an unauthenticated user to potentially
| enable denial of service via adjacent access.


CVE-2023-28720[6]:
| Improper initialization for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access..


CVE-2023-28374[7]:
| Improper input validation for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow
| an unauthenticated user to potentially enable denial of service via
| adjacent access.


CVE-2023-26586[8]:
| Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R)
| Killer(TM) Wi-Fi software before version 22.240 may allow an
| unauthenticated user to potentially enable denial of service via
| adjacent access.


CVE-2023-25951[9]:
| Improper input validation for some Intel(R) PROSet/Wireless and
| Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a
| privileged user to potentially enable escalation of privilege via
| local access.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-35061
    https://www.cve.org/CVERecord?id=CVE-2023-35061
[1] https://security-tracker.debian.org/tracker/CVE-2023-34983
    https://www.cve.org/CVERecord?id=CVE-2023-34983
[2] https://security-tracker.debian.org/tracker/CVE-2023-33875
    https://www.cve.org/CVERecord?id=CVE-2023-33875
[3] https://security-tracker.debian.org/tracker/CVE-2023-32651
    https://www.cve.org/CVERecord?id=CVE-2023-32651
[4] https://security-tracker.debian.org/tracker/CVE-2023-32644
    https://www.cve.org/CVERecord?id=CVE-2023-32644
[5] https://security-tracker.debian.org/tracker/CVE-2023-32642
    https://www.cve.org/CVERecord?id=CVE-2023-32642
[6] https://security-tracker.debian.org/tracker/CVE-2023-28720
    https://www.cve.org/CVERecord?id=CVE-2023-28720
[7] https://security-tracker.debian.org/tracker/CVE-2023-28374
    https://www.cve.org/CVERecord?id=CVE-2023-28374
[8] https://security-tracker.debian.org/tracker/CVE-2023-26586
    https://www.cve.org/CVERecord?id=CVE-2023-26586
[9] https://security-tracker.debian.org/tracker/CVE-2023-25951
    https://www.cve.org/CVERecord?id=CVE-2023-25951

Regards,
Salvatore

[toc] | [next] | [standalone]


#82896

FromSalvatore Bonaccorso <carnil@debian.org>
Date2024-06-30 21:00 +0200
Message-ID<IV7Wh-6K5l-3@gated-at.bofh.it>
In reply to#81902
Control: retitle -1 firmware-nonfree: CVE-2023-35061

Hi Ben,

On Sun, Jun 30, 2024 at 08:42:32PM +0200, Ben Hutchings wrote:
> On Sun, 18 Feb 2024 20:45:07 +0100 Salvatore Bonaccorso
> <carnil@debian.org> wrote:
> > Source: firmware-nonfree
> > Version: 20230625-2
> > Severity: important
> > Tags: security upstream
> > X-Debbugs-Cc: carnil@debian.org, Debian Security Team
> <team@security.debian.org>
> > 
> > Hi,
> > 
> > The following vulnerabilities were published for firmware-nonfree.
> > 
> > They are addressed in the linux-firmware/20231211 upstream version.
> [...]
> 
> According to
> <https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00947.html>
> only CVE-2023-35061 affects Linux (presumably the other issues are in
> the Windows driver, not the firmware).

You are right. I'm not sure if that information was already
availablewhen filling the bug, bug surely I will now fix the tracker
information then to only reflect it for CVE-2023-35061.

Thanks for the headsup!

Salvatore

[toc] | [prev] | [next] | [standalone]


#82897 — Processed: Re: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-06-30 21:00 +0200
SubjectProcessed: Re: firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951
Message-ID<IV7Wi-6K5l-7@gated-at.bofh.it>
In reply to#81902
Processing control commands:

> retitle -1 firmware-nonfree: CVE-2023-35061
Bug #1064229 [src:firmware-nonfree] firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951
Changed Bug title to 'firmware-nonfree: CVE-2023-35061' from 'firmware-nonfree: CVE-2023-35061 CVE-2023-34983 CVE-2023-33875 CVE-2023-32651 CVE-2023-32644 CVE-2023-32642 CVE-2023-28720 CVE-2023-28374 CVE-2023-26586 CVE-2023-25951'.

-- 
1064229: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064229
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#83006 — Bug#1064229: marked as done (firmware-nonfree: CVE-2023-35061)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2024-07-15 22:50 +0200
SubjectBug#1064229: marked as done (firmware-nonfree: CVE-2023-35061)
Message-ID<J0ANX-2ntD-5@gated-at.bofh.it>
In reply to#81902

[Multipart message — attachments visible in raw view] — view raw

Your message dated Mon, 15 Jul 2024 20:45:46 +0000
with message-id <E1sTSZu-00DUy8-Gi@fasolo.debian.org>
and subject line Bug#1064229: fixed in firmware-nonfree 20240610-1
has caused the Debian Bug report #1064229,
regarding firmware-nonfree: CVE-2023-35061
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1064229: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1064229
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web