Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1413697 > unrolled thread

Re: Patch for CVE-2016-0774 missing from stable 3.4 and 3.10 kernels

Started byWilly Tarreau <w@1wt.eu>
First post2016-06-04 13:40 +0200
Last post2016-06-04 21:40 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: Patch for CVE-2016-0774 missing from stable 3.4 and 3.10 kernels Willy Tarreau <w@1wt.eu> - 2016-06-04 13:40 +0200
    Re: Patch for CVE-2016-0774 missing from stable 3.4 and 3.10 kernels Greg KH <gregkh@linuxfoundation.org> - 2016-06-04 21:40 +0200

#1413697 — Re: Patch for CVE-2016-0774 missing from stable 3.4 and 3.10 kernels

FromWilly Tarreau <w@1wt.eu>
Date2016-06-04 13:40 +0200
SubjectRe: Patch for CVE-2016-0774 missing from stable 3.4 and 3.10 kernels
Message-ID<rGi5Q-8on-7@gated-at.bofh.it>
Hi,

On Mon, Mar 28, 2016 at 04:53:48PM -0700, Jeffrey Vander Stoep wrote:
> https://lkml.org/lkml/2016/2/23/812 "pipe: Fix buffer offset after
> partially failed read" is missing from the stable 3.4.y and 3.10.y
> kernels. It has been included in 3.2.y and 3.14.y.
> 
> I am able to cause a kernel panic without this patch.

Just a heads up on this one, it is *not* included in 3.14 as of 3.14.71.
It's in 3.2 and 3.4 however. Greg, you can pick commit feae3ca2e5e1a
from kernel 3.2, it will apply with an offset.

Regards,
Willy

[toc] | [next] | [standalone]


#1413848

FromGreg KH <gregkh@linuxfoundation.org>
Date2016-06-04 21:40 +0200
Message-ID<rGpAm-57V-15@gated-at.bofh.it>
In reply to#1413697
On Sat, Jun 04, 2016 at 01:33:21PM +0200, Willy Tarreau wrote:
> Hi,
> 
> On Mon, Mar 28, 2016 at 04:53:48PM -0700, Jeffrey Vander Stoep wrote:
> > https://lkml.org/lkml/2016/2/23/812 "pipe: Fix buffer offset after
> > partially failed read" is missing from the stable 3.4.y and 3.10.y
> > kernels. It has been included in 3.2.y and 3.14.y.
> > 
> > I am able to cause a kernel panic without this patch.
> 
> Just a heads up on this one, it is *not* included in 3.14 as of 3.14.71.
> It's in 3.2 and 3.4 however. Greg, you can pick commit feae3ca2e5e1a
> from kernel 3.2, it will apply with an offset.

Ugh, sorry about that, I thought I picked it up, my fault.  thanks for
pointing it out, now queued up.

greg k-h

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web