oss-sec mailing list archives

Re: Netlink XFRM socket subsystem NULL pointer dereference


From: Marius Bakke <mbakke () fastmail com>
Date: Sun, 22 Oct 2017 13:21:19 +0200

Noam Rathaus <noamr () beyondsecurity com> writes:

Hi,

I was forwarded by:
Dan Carpenter <dan.carpenter () oracle com>

To you regarding obtaining a CVE for the mentioned (in the title)
vulnerability

I know a patch is being created and placed into mainstream code of the
Kernel

I would like also to get a CVE for it, so that we can put that in the
advisory we will release

Unfortunately CVE IDs are not assigned through this list anymore.
Please use <https://cveform.mitre.org/> to request a CVE.

Do we need to give you the full technical writeup of the vulnerability?

It's by no means required, but it would be appreciated if you could get
back to this list with the advisory and CVE identifier when ready.

Attachment: signature.asc
Description:


Current thread: