public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: Jan Beulich <jbeulich@suse.com>
Cc: cve@kernel.org, linux-kernel@vger.kernel.org,
	"security@xenproject.org" <security@xenproject.org>,
	Juergen Gross <jgross@suse.com>
Subject: Re: CVE-2021-47573: xen/blkfront: harden blkfront against event channel storms
Date: Thu, 20 Jun 2024 11:20:32 +0200	[thread overview]
Message-ID: <2024062025-uncivil-sterile-03f7@gregkh> (raw)
In-Reply-To: <ac40bf5e-6537-4ef5-bac9-afbe512a9d70@suse.com>

On Thu, Jun 20, 2024 at 10:46:10AM +0200, Jan Beulich wrote:
> On 20.06.2024 10:18, Greg Kroah-Hartman wrote:
> > Also, the XSA-391 announcement doesn't say anything about them either,
> > is that intentional?
> 
> If by announcement you mean the email sent out to xen-security-issues@lists.xen.org,
> then the copy I'm looking at (v3, the only one having gone public afaict) clearly
> lists the three CVEs.

I'm looking at:
	https://xenbits.xen.org/xsa/advisory-391.html
and I don't see a git id anywhere, where do you see the v3 announcement
saying that?

Also, the json file at:
	https://www.cve.org/CVERecord?id=CVE-2021-28711
points to:
	https://xenbits.xenproject.org/xsa/advisory-391.txt
Not to the html document, which is correct?

But to be fair, I'm not going to be able to search all links in all json
files for all entries, so even if the 391 announcement did show the git
ids for the changes, I would miss it.  All I can do is search the json
repo for all CVEs.

thanks,

greg k-h

  reply	other threads:[~2024-06-20  9:20 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <2024061911-CVE-2021-47573-5c43@gregkh>
2024-06-20  7:53 ` CVE-2021-47573: xen/blkfront: harden blkfront against event channel storms Juergen Gross
2024-06-20  8:18   ` Greg Kroah-Hartman
2024-06-20  8:46     ` Jan Beulich
2024-06-20  9:20       ` Greg Kroah-Hartman [this message]
2024-06-20  9:32         ` Jan Beulich
2024-06-20  9:41           ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2024062025-uncivil-sterile-03f7@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=jbeulich@suse.com \
    --cc=jgross@suse.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=security@xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox