Date: Tue, 27 Apr 2010 09:45:39 +0300 From: Eren Türkay <eren@...dus.org.tr> To: oss-security@...ts.openwall.com Subject: Re: CVE request: kernel: tty: release_one_tty() forgets to put pids On Thu, Apr 15, 2010 at 08:44:53AM +0800, Eugene Teo wrote: > pgrp member in struct tty_struct was converted to struct pid in > commit ab521dc0, so kernels of version v2.6.26-rc1 and above are > affected by this. FYI. We use v188.8.131.52 in one of our products. As far as I see from include/linux/tty.h in 2.6.25 archive that pgrp member in tty_struct is already converted to "struct pid". I haven't checked the older kernel releases but this issue exists in 2.6.25. It would be very helpful if someone checked older kernel releases to correctly determine which releases are vulnerable. Regards, Eren
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.