Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 28 May 2021 18:19:30 +0200
From: Marc Kleine-Budde <mkl@...gutronix.de>
To: Oliver Hartkopp <socketcan@...tkopp.net>
Cc: Greg Kroah-Hartman <gregkh@...uxfoundation.org>, alex.popov@...ux.com,
	seth.arnold@...onical.com, steve.beattie@...onical.com,
	cascardo@...onical.com, oss-security@...ts.openwall.com,
	Norbert Slusarek <nslusarek@....net>,
	"David S. Miller" <davem@...emloft.net>,
	Jakub Kicinski <kuba@...nel.org>, security@...nel.org
Subject: Re: Linux kernel: net/can/isotp: race condition leads to local
 privilege escalation

On 28.05.2021 17:41:03, Oliver Hartkopp wrote:
> this patch ("can: isotp: prevent race between isotp_bind() and
> isotp_setsockopt()") has hit Linus' tree ~36h ago:
> 
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/can?id=2b17c400aeb44daf041627722581ade527bb3c1d
> 
> It has a CVE number and is potentially exploitable - but it was not in the
> latest batch of stable kernels about ~4h ago.
> 
> It was obviously not tagged properly for stable kernels but has a
> fixes-tag:

Oh - there was a change if networking stable handling:

| dbbe7c962c3a docs: networking: drop special stable handling

I've missed the memo, sorry.

regards,
Marc

-- 
Pengutronix e.K.                 | Marc Kleine-Budde           |
Embedded Linux                   | https://www.pengutronix.de  |
Vertretung West/Dortmund         | Phone: +49-231-2826-924     |
Amtsgericht Hildesheim, HRA 2686 | Fax:   +49-5121-206917-5555 |

Download attachment "signature.asc" of type "application/pgp-signature" (489 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.