[kernel-sec-discuss] r1872 - active retired

Moritz Muehlenhoff jmm at alioth.debian.org
Tue Jul 6 06:48:07 UTC 2010


Author: jmm
Date: 2010-07-06 06:48:06 +0000 (Tue, 06 Jul 2010)
New Revision: 1872

Added:
   retired/CVE-2008-7256
   retired/CVE-2010-1643
   retired/CVE-2010-2071
Removed:
   active/CVE-2008-7256
   active/CVE-2010-1643
   active/CVE-2010-2071
Log:
retire issues


Deleted: active/CVE-2008-7256
===================================================================
--- active/CVE-2008-7256	2010-07-06 06:47:24 UTC (rev 1871)
+++ active/CVE-2008-7256	2010-07-06 06:48:06 UTC (rev 1872)
@@ -1,19 +0,0 @@
-Candidate: CVE-2008-7256
-Description:
- mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled
- and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs 
- objects by knfsd, which allows attackers to cause a denial of service (NULL pointer
- dereference and knfsd crash) or possibly have unspecified other impact via unknown
- vectors. NOTE: this vulnerability exists of an incomplete fix for CVE-2010-1643.
-References:
- http://www.openwall.com/lists/oss-security/2010/05/27/1
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1b79cd04fab80be61dcd2732e2423aafde9a4c1c
- http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.28/ChangeLog-2.6.28-rc8
- https://bugzilla.redhat.com/show_bug.cgi?id=595970
-Notes:
-Bugs:
-upstream: released (2.6.28)
-2.6.32-upstream-stable: N/A
-linux-2.6: released (2.6.28-1)
-2.6.26-lenny-security: released (2.6.26-23) [bugfix/all/nfsd-fix-vm-overcommit-crash-2.patch]
-2.6.32-squeeze-security: N/A

Deleted: active/CVE-2010-1643
===================================================================
--- active/CVE-2010-1643	2010-07-06 06:47:24 UTC (rev 1871)
+++ active/CVE-2010-1643	2010-07-06 06:48:06 UTC (rev 1872)
@@ -1,13 +0,0 @@
-Candidate: CVE-2010-1643
-Description:
- mm dos
-References:
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1643
-Notes:
- jmm> Also 1b79cd04fab80be61dcd2732e2423aafde9a4c1c per oss-sec
-Bugs:
-upstream: released (2.6.28) [731572d39]
-2.6.32-upstream-stable: N/A
-linux-2.6: released (2.6.28-1)
-2.6.26-lenny-security: released (2.6.26-23) [bugfix/all/nfsd-fix-vm-overcommit-crash.patch]
-2.6.32-squeeze-security: N/A

Deleted: active/CVE-2010-2071
===================================================================
--- active/CVE-2010-2071	2010-07-06 06:47:24 UTC (rev 1871)
+++ active/CVE-2010-2071	2010-07-06 06:48:06 UTC (rev 1872)
@@ -1,13 +0,0 @@
-Candidate: CVE-2010-2071
-Description:
-References:
- http://www.openwall.com/lists/oss-security/2010/06/11/3
- http://lkml.org/lkml/2010/5/17/544 
- http://git.kernel.org/linus/2f26afba
-Notes:
-Bugs:
-upstream: released (2.6.35-rc3) [2f26afba]
-2.6.32-upstream-stable: released (2.6.32.16)
-linux-2.6: released (2.6.32-16)
-2.6.26-lenny-security: N/A "no btrfs"
-2.6.32-squeeze-security: released (2.6.32-16)

Copied: retired/CVE-2008-7256 (from rev 1870, active/CVE-2008-7256)
===================================================================
--- retired/CVE-2008-7256	                        (rev 0)
+++ retired/CVE-2008-7256	2010-07-06 06:48:06 UTC (rev 1872)
@@ -0,0 +1,19 @@
+Candidate: CVE-2008-7256
+Description:
+ mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled
+ and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs 
+ objects by knfsd, which allows attackers to cause a denial of service (NULL pointer
+ dereference and knfsd crash) or possibly have unspecified other impact via unknown
+ vectors. NOTE: this vulnerability exists of an incomplete fix for CVE-2010-1643.
+References:
+ http://www.openwall.com/lists/oss-security/2010/05/27/1
+ http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=1b79cd04fab80be61dcd2732e2423aafde9a4c1c
+ http://www.kernel.org/pub/linux/kernel/v2.6/testing/v2.6.28/ChangeLog-2.6.28-rc8
+ https://bugzilla.redhat.com/show_bug.cgi?id=595970
+Notes:
+Bugs:
+upstream: released (2.6.28)
+2.6.32-upstream-stable: N/A
+linux-2.6: released (2.6.28-1)
+2.6.26-lenny-security: released (2.6.26-23) [bugfix/all/nfsd-fix-vm-overcommit-crash-2.patch]
+2.6.32-squeeze-security: N/A


Property changes on: retired/CVE-2008-7256
___________________________________________________________________
Added: svn:mergeinfo
   + 

Copied: retired/CVE-2010-1643 (from rev 1871, active/CVE-2010-1643)
===================================================================
--- retired/CVE-2010-1643	                        (rev 0)
+++ retired/CVE-2010-1643	2010-07-06 06:48:06 UTC (rev 1872)
@@ -0,0 +1,13 @@
+Candidate: CVE-2010-1643
+Description:
+ mm dos
+References:
+ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1643
+Notes:
+ jmm> Also 1b79cd04fab80be61dcd2732e2423aafde9a4c1c per oss-sec
+Bugs:
+upstream: released (2.6.28) [731572d39]
+2.6.32-upstream-stable: N/A
+linux-2.6: released (2.6.28-1)
+2.6.26-lenny-security: released (2.6.26-23) [bugfix/all/nfsd-fix-vm-overcommit-crash.patch]
+2.6.32-squeeze-security: N/A


Property changes on: retired/CVE-2010-1643
___________________________________________________________________
Added: svn:mergeinfo
   + 

Copied: retired/CVE-2010-2071 (from rev 1869, active/CVE-2010-2071)
===================================================================
--- retired/CVE-2010-2071	                        (rev 0)
+++ retired/CVE-2010-2071	2010-07-06 06:48:06 UTC (rev 1872)
@@ -0,0 +1,13 @@
+Candidate: CVE-2010-2071
+Description:
+References:
+ http://www.openwall.com/lists/oss-security/2010/06/11/3
+ http://lkml.org/lkml/2010/5/17/544 
+ http://git.kernel.org/linus/2f26afba
+Notes:
+Bugs:
+upstream: released (2.6.35-rc3) [2f26afba]
+2.6.32-upstream-stable: released (2.6.32.16)
+linux-2.6: released (2.6.32-16)
+2.6.26-lenny-security: N/A "no btrfs"
+2.6.32-squeeze-security: released (2.6.32-16)


Property changes on: retired/CVE-2010-2071
___________________________________________________________________
Added: svn:mergeinfo
   + 




More information about the kernel-sec-discuss mailing list