Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 19 Jan 2016 12:00:57 -0500
From: Josh Boyer <jwboyer@...oraproject.org>
To: Peter Hurley <peter@...leysoftware.com>
Cc: Dan Carpenter <dan.carpenter@...cle.com>, 
	"Linux-Kernel@...r. Kernel. Org" <linux-kernel@...r.kernel.org>, kernel-hardening@...ts.openwall.com, 
	Greg KH <gregkh@...uxfoundation.org>
Subject: Re: 2015 kernel CVEs

On Tue, Jan 19, 2016 at 11:57 AM, Peter Hurley <peter@...leysoftware.com> wrote:
> On 01/19/2016 03:28 AM, Dan Carpenter wrote:
>> I like to look back over old CVEs to see how we could do better.  Here
>> is the list from 2015.  I got most of this information from the Ubuntu
>> CVE tracker.  Thanks Ubuntu!.  If it doesn't have a hash that means it
>> might not be fixed yet.
>
> [...]
>
>> CVE-2015-4170 cf872776fc84: tty: hang in tty
>
> Makes no sense that this was assigned a CVE.
> I fixed this _2 yrs before_ it was reported and the patch was CC'd stable.

I'm guessing the CVE was assigned because there are distributions that
ship based on kernels earlier than 3.13.  Those distributors need to
verify if they have the fix, etc.

josh

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.