Date: Fri, 24 Jun 2011 12:25:39 +0800 From: Eugene Teo <eugene@...hat.com> To: oss-security@...ts.openwall.com CC: Kees Cook <kees@...ntu.com>, "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE request: kernel: ext4: init timer earlier to avoid a kernel panic in __save_error_info On 06/24/2011 05:38 AM, Kees Cook wrote: > This came to our attention: > http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=0449641130f5 > by way of https://bugs.launchpad.net/ubuntu/+source/linux/+bug/801087 and > https://bugzilla.kernel.org/show_bug.cgi?id=32082 > > "During mount, when we fail to open journal inode or root inode, the > __save_error_info will mod_timer. But actually s_err_report isn't > initialized yet and the kernel oops." Please use this CVE-2011-2493. Thanks, Eugene
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.