Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1642217

Re: CVE-2016-10229 in 4.4.x series

From Willy Tarreau <w@1wt.eu>
Newsgroups linux.kernel
Subject Re: CVE-2016-10229 in 4.4.x series
Date 2017-05-16 07:30 +0200
Message-ID <tHDdw-1qC-13@gated-at.bofh.it> (permalink)
References <tHzjA-7hu-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, May 15, 2017 at 06:09:53PM -0700, Steven Pease wrote:
> Hi,
> 
> This is my first post - not currently subscribed so please CC me. :) I
> searched a bit for this question, but couldn't find an answer (Googled
> '2016-10229 site:lkml.org').
> 
> Does CVE-2016-10229 affect the newest version of the 4.4.x kernel
> series (currently 4.4.68) and are there any plans to fix this in the
> 4.4 kernel series?

This one was fixed by upstream commit 197c949 ("udp: properly support
MSG_PEEK with truncated buffers"), which was backported in 4.4 as
commit dfe2042d96 in 4.4.21. So in short, 4.4.68 is safe.

Willy

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

CVE-2016-10229 in 4.4.x series Steven Pease <spease@suitabletech.com> - 2017-05-16 03:20 +0200
  Re: CVE-2016-10229 in 4.4.x series Willy Tarreau <w@1wt.eu> - 2017-05-16 07:30 +0200
    Re: CVE-2016-10229 in 4.4.x series Steven Pease <spease@suitabletech.com> - 2017-05-16 08:00 +0200
      Re: CVE-2016-10229 in 4.4.x series Willy Tarreau <w@1wt.eu> - 2017-05-16 08:10 +0200

csiph-web