Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 22 May 2019 21:41:21 +0200
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Linux kernel < 4.8 local generic ASLR - another CVE-ID

On Thu, Apr 18, 2019 at 09:40:54AM -0400, Vladis Dronov wrote:
> Just in another case - this flaw in a.out binaries has got the CVE-2019-11191:
> 
> http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11191

Dongguangdong of Huawei PSIRT discovered and reported to linux-distros
on May 6 that this additionally affects flat binaries, binfmt_flat.c.

Since we're now past linux-distros' 14 days max embargo period and since
Dongguangdong failed to bring this in here on time, I felt I had to take
over and post the above now.

Personally, I find this a very minor detail, but I like (linux-)distros
policy to be adhered to without exceptions.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.