Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 24 Jun 2011 12:25:39 +0800
From: Eugene Teo <eugene@...hat.com>
To: oss-security@...ts.openwall.com
CC: Kees Cook <kees@...ntu.com>, "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request: kernel: ext4: init timer earlier
 to avoid a kernel panic in __save_error_info

On 06/24/2011 05:38 AM, Kees Cook wrote:
> This came to our attention:
> http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=0449641130f5
> by way of https://bugs.launchpad.net/ubuntu/+source/linux/+bug/801087 and
> https://bugzilla.kernel.org/show_bug.cgi?id=32082
> 
> "During mount, when we fail to open journal inode or root inode, the
> __save_error_info will mod_timer. But actually s_err_report isn't
> initialized yet and the kernel oops."

Please use this CVE-2011-2493.

Thanks, Eugene

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.