Add NEWS entry for CVE-2020-6096 (bug 25620)

Reviewed-by: Carlos O'Donell <carlos@redhat.com>

(cherry picked from commit 17400c4bcd57d84add1da3aa93248ef2efdb0ccb)
This commit is contained in:
Aurelien Jarno 2020-07-12 21:58:43 +02:00
parent 64246fccaf
commit 6f3459f985

5
NEWS
View File

@ -37,6 +37,11 @@ Security related changes:
CVE-2020-1752: A use-after-free vulnerability in the glob function when
expanding ~user has been fixed.
CVE-2020-6096: A signed comparison vulnerability in the ARMv7 memcpy and
memmove functions has been fixed. Discovered by Jason Royes and Samual
Dytrych of the Cisco Security Assessment and Penetration Team (See
TALOS-2020-1019).
Version 2.31