Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1642229
| Path | csiph.com!news.redatomik.org!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | Steven Pease <spease@suitabletech.com> |
| Newsgroups | linux.kernel |
| Subject | Re: CVE-2016-10229 in 4.4.x series |
| Date | Tue, 16 May 2017 08:00:02 +0200 |
| Message-ID | <tHDGy-1Df-7@gated-at.bofh.it> (permalink) |
| References | <tHzjA-7hu-9@gated-at.bofh.it> <tHDdw-1qC-13@gated-at.bofh.it> |
| Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=suitabletech.com; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=qtYJBi/DEd+rU9v9aPhlluw0MTLG1Z7KJAARdrFeF9E=; b=fpirtT4E5oK5OcUkK77wdrgqx7uyTbOBL62VWAaPhtOUhDC3JpA7DQdZXHIhEIovTt a+Q4LKRFC4XWylIPH0es59Et9VzX3c36y9+4UytpmVQ86OjfZQwiDUW/fJB/4EKwAasg AhcHaFXOpbdWGsRJzHCmH1+6LGfXQ0Y3/AiEI= |
| X-Google-Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=qtYJBi/DEd+rU9v9aPhlluw0MTLG1Z7KJAARdrFeF9E=; b=MiadVKOQ73vL/PGTk0/nhpR9XiQsHA32UKF0WP0fnzNWpYkPCcsHDTcaYWUi4akDpX YQSRHrTTCxicdXJJk2qIOUf1t+NhNgnR0V2ZsS8vs0EFFfNRupSZVqgIpFlfbSHDsunn dkvwh9iN9WkUaTuEV/8ltcsVKpEDR+j+WAiL0jZS1PIS98vRaqgh1orEfJKj2c9KdRQ7 or/ZmrSwjEjVFaZ6qkr29ZFVt/NV44OO6gnQoDXd2cqeUPeEEDAMDDgqrlhRg7dTPsxt WUyYCyWP1v6K+DKiQrdxoctFpO4DS1QfnMkDkoFn2HBMBVIrF4iAgVUK/LYrFnK/ROof /DzA== |
| X-Gm-Message-State | AODbwcAsghk07U0aB6Y/d3RlbOD9nKHDEobl9M6la36qaEXNQNGmx+I9 Dny8NyweDDMhzN1qiD/sze47HlGSWGYCYLpUvw== |
| X-Received | by 10.37.250.26 with SMTP id b26mr8041424ybe.98.1494914030777; Mon, 15 May 2017 22:53:50 -0700 (PDT) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset="UTF-8" |
| Sender | robomod@news.nic.it |
| List-ID | <linux-kernel.vger.kernel.org> |
| X-Mailing-List | linux-kernel@vger.kernel.org |
| Approved | robomod@news.nic.it |
| Lines | 29 |
| Organization | linux.* mail to news gateway |
| X-Original-Cc | linux-kernel@vger.kernel.org |
| X-Original-Date | Mon, 15 May 2017 22:53:50 -0700 |
| X-Original-Message-ID | <CALQ-SODhbky=pHUK1c6S91OE0H+kBS=7UATSNBud82a-hAunQA@mail.gmail.com> |
| X-Original-References | <CALQ-SOCrEyJ9TQMKT8EdvjAJ_cY-6t48kfWs_VJ=FNn90ZPmGw@mail.gmail.com> <20170516052009.GA17400@1wt.eu> |
| X-Original-Sender | linux-kernel-owner@vger.kernel.org |
| Xref | csiph.com linux.kernel:1642229 |
Show key headers only | View raw
Is there any particular reason that the CVE appears to be filed
against 4.4.60? Or is this just a mistake?
http://www.cvedetails.com/cve/CVE-2016-10229/
- Steven
On Mon, May 15, 2017 at 10:20 PM, Willy Tarreau <w@1wt.eu> wrote:
> On Mon, May 15, 2017 at 06:09:53PM -0700, Steven Pease wrote:
>> Hi,
>>
>> This is my first post - not currently subscribed so please CC me. :) I
>> searched a bit for this question, but couldn't find an answer (Googled
>> '2016-10229 site:lkml.org').
>>
>> Does CVE-2016-10229 affect the newest version of the 4.4.x kernel
>> series (currently 4.4.68) and are there any plans to fix this in the
>> 4.4 kernel series?
>
> This one was fixed by upstream commit 197c949 ("udp: properly support
> MSG_PEEK with truncated buffers"), which was backported in 4.4 as
> commit dfe2042d96 in 4.4.21. So in short, 4.4.68 is safe.
>
> Willy
--
- Steven
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
CVE-2016-10229 in 4.4.x series Steven Pease <spease@suitabletech.com> - 2017-05-16 03:20 +0200
Re: CVE-2016-10229 in 4.4.x series Willy Tarreau <w@1wt.eu> - 2017-05-16 07:30 +0200
Re: CVE-2016-10229 in 4.4.x series Steven Pease <spease@suitabletech.com> - 2017-05-16 08:00 +0200
Re: CVE-2016-10229 in 4.4.x series Willy Tarreau <w@1wt.eu> - 2017-05-16 08:10 +0200
csiph-web