Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #73863 > unrolled thread

Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object

Started by"Jeremiah C. Foster" <jeremiah@jeremiahfoster.com>
First post2021-11-30 19:10 +0100
Last post2021-11-30 21:10 +0100
Articles 4 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object "Jeremiah C. Foster" <jeremiah@jeremiahfoster.com> - 2021-11-30 19:10 +0100
    Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object Salvatore Bonaccorso <carnil@debian.org> - 2021-11-30 21:10 +0100
      Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object "Jeremiah C. Foster" <jeremiah@jeremiahfoster.com> - 2021-12-01 01:10 +0100
    Processed: Re: Bug#1000886: CVE-2013-7445: Direct Rendering  Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles  requests for GEM object "Debian Bug Tracking System" <owner@bugs.debian.org> - 2021-11-30 21:10 +0100

#73863 — Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object

From"Jeremiah C. Foster" <jeremiah@jeremiahfoster.com>
Date2021-11-30 19:10 +0100
SubjectBug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object
Message-ID<DpfJM-ve-9@gated-at.bofh.it>
Package: linux
Source: linux
Version: 4.0
Severity: important
Tags: upstream

Dear Maintainer,

There is a list of unreported issues in the Debian Security-tracker:
https://security-tracker.debian.org/tracker/status/unreported This
issue was the first one in the tracker which led me to file this issue

in Debian's bug tracking system.

Regards,

Jeremiah

-- System Information:
Debian Release: 11.1
   APT prefers stable-updates
   APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500,
'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-9-amd64 (SMP w/8 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US.UTF-8
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

[toc] | [next] | [standalone]


#73869

FromSalvatore Bonaccorso <carnil@debian.org>
Date2021-11-30 21:10 +0100
Message-ID<DphBT-1BL-1@gated-at.bofh.it>
In reply to#73863
Control: tags -1 + security
Control: notfound -1 4.0

Hi Jeremiah,

On Tue, Nov 30, 2021 at 12:56:50PM -0500, Jeremiah C. Foster wrote:
> Package: linux
> Source: linux
> Version: 4.0
> Severity: important
> Tags: upstream
> 
> Dear Maintainer,
> 
> There is a list of unreported issues in the Debian Security-tracker:
> https://security-tracker.debian.org/tracker/status/unreported This
> issue was the first one in the tracker which led me to file this issue
> 
> in Debian's bug tracking system.

Thank you. It's usually not necessary to fill bugs for CVEs for
src:linux, we are already tracking them and are aware. In the
particular case you can look up  CVE-2013-7445 and it's unlikely that
it will be addressed. Furthermore CVEs for linux are specifically
tracked in the kernel-team as well.


It's not necessary to fill bugs for CVE for src:linux, we already
track them, so this would just cause some unnecessary overhead (in
particular for such on old CVE ;-)).

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#73874

From"Jeremiah C. Foster" <jeremiah@jeremiahfoster.com>
Date2021-12-01 01:10 +0100
Message-ID<Dplm9-3QW-3@gated-at.bofh.it>
In reply to#73869
On 11/30/21 3:02 PM, Salvatore Bonaccorso wrote:
> Control: tags -1 + security
> Control: notfound -1 4.0

Hi Salvatore,

Thank you for your reply.

> Thank you. It's usually not necessary to fill bugs for CVEs for
> src:linux, we are already tracking them and are aware.  > In the

Sorry for the noise.

> particular case you can look up  CVE-2013-7445 and it's unlikely that
> it will be addressed. Furthermore CVEs for linux are specifically
> tracked in the kernel-team as well.

What about the other CVEs in the unreported list? 
(https://security-tracker.debian.org/tracker/status/unreported) Is it 
worthwhile to try to get them reported? Or is this a low priority 
because they've already been triaged?

Thanks again,

Jeremiah

[toc] | [prev] | [next] | [standalone]


#73870 — Processed: Re: Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2021-11-30 21:10 +0100
SubjectProcessed: Re: Bug#1000886: CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object
Message-ID<DphBU-1BL-7@gated-at.bofh.it>
In reply to#73863
Processing control commands:

> tags -1 + security
Bug #1000886 [src:linux] CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object
Added tag(s) security.
> notfound -1 4.0
Bug #1000886 [src:linux] CVE-2013-7445: Direct Rendering Manager (DRM) subsystem in the Linux Kernel through 4.x mishandles requests for GEM object
The source 'linux' and version '4.0' do not appear to match any binary packages
No longer marked as found in versions linux/4.0.

-- 
1000886: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1000886
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web