From 17400c4bcd57d84add1da3aa93248ef2efdb0ccb Mon Sep 17 00:00:00 2001 From: Aurelien Jarno Date: Sun, 12 Jul 2020 21:58:43 +0200 Subject: Add NEWS entry for CVE-2020-6096 (bug 25620) Reviewed-by: Carlos O'Donell --- NEWS | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'NEWS') diff --git a/NEWS b/NEWS index 81b014a7ee..5051e804ea 100644 --- a/NEWS +++ b/NEWS @@ -174,6 +174,11 @@ Security related changes: CVE-2020-1752: A use-after-free vulnerability in the glob function when expanding ~user has been fixed. + CVE-2020-6096: A signed comparison vulnerability in the ARMv7 memcpy and + memmove functions has been fixed. Discovered by Jason Royes and Samual + Dytrych of the Cisco Security Assessment and Penetration Team (See + TALOS-2020-1019). + The following bugs are resolved with this release: [The release manager will add the list generated by -- cgit 1.4.1