Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 24 Jun 2011 12:25:39 +0800
From: Eugene Teo <eugene@...hat.com>
To: oss-security@...ts.openwall.com
CC: Kees Cook <kees@...ntu.com>, "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request: kernel: ext4: init timer earlier
 to avoid a kernel panic in __save_error_info

On 06/24/2011 05:38 AM, Kees Cook wrote:
> This came to our attention:
> http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=0449641130f5
> by way of https://bugs.launchpad.net/ubuntu/+source/linux/+bug/801087 and
> https://bugzilla.kernel.org/show_bug.cgi?id=32082
> 
> "During mount, when we fail to open journal inode or root inode, the
> __save_error_info will mod_timer. But actually s_err_report isn't
> initialized yet and the kernel oops."

Please use this CVE-2011-2493.

Thanks, Eugene

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ