[kernel-sec-discuss] r3660 - active

Ben Hutchings benh at moszumanska.debian.org
Thu Jan 29 02:26:22 UTC 2015


Author: benh
Date: 2015-01-29 02:26:22 +0000 (Thu, 29 Jan 2015)
New Revision: 3660

Modified:
   active/CVE-2014-7822
Log:
Add information about effects of CVE-2014-7822

Modified: active/CVE-2014-7822
===================================================================
--- active/CVE-2014-7822	2015-01-29 01:02:19 UTC (rev 3659)
+++ active/CVE-2014-7822	2015-01-29 02:26:22 UTC (rev 3660)
@@ -1,12 +1,15 @@
 Description: splice: lack of generic write checks
 References:
 Notes:
+ bwh> I have a reproducer for this.  On 2.6.32 it causes ext4 to corrupt
+ bwh> the filesystem (which is caught by e2fsck).  On 3.2 it causes ext4 to
+ bwh> hang on umount.  ext3 and xfs don't seem to be affected.
 Bugs:
  - https://bugzilla.redhat.com/show_bug.cgi?id=1163792
 upstream: released (v3.16-rc1) [8d0207652cbe27d1f962050737848e5ad4671958]
-2.6.32-upstream-stable:
+2.6.32-upstream-stable: needed
 sid: released (3.16.2-1)
-3.2-wheezy-security:
-2.6.32-squeeze-security:
-3.16-upstream-stable:
-3.2-upstream-stable:
+3.2-wheezy-security: needed
+2.6.32-squeeze-security: needed
+3.16-upstream-stable: N/A "fixed before 3.16"
+3.2-upstream-stable: needed




More information about the kernel-sec-discuss mailing list