Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 15 Aug 2011 15:43:01 +0200
From: Petr Matousek <pmatouse@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley@...us.mitre.org
Subject: CVE request -- kernel: perf: fix software event overflow

Hello Steve, vendors.

Description:
Under certain circumstances software event overflows go wrong and
deadlock. Avoid trying to delete a timer from the timer callback.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=730706
https://lkml.org/lkml/2011/7/27/337 (reproducer)
https://lkml.org/lkml/2011/7/28/284 (fix)

Upstream fix:
a8b0ca17b80e92faab46ee7179ba9e99ccb61233 (much larger patch that
contains the hunk referenced above)

Thank you,
-- 
Petr Matousek / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.