Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1642154 > unrolled thread

CVE-2016-10229 in 4.4.x series

Started bySteven Pease <spease@suitabletech.com>
First post2017-05-16 03:20 +0200
Last post2017-05-16 08:10 +0200
Articles 4 — 2 participants

Back to article view | Back to linux.kernel


Contents

  CVE-2016-10229 in 4.4.x series Steven Pease <spease@suitabletech.com> - 2017-05-16 03:20 +0200
    Re: CVE-2016-10229 in 4.4.x series Willy Tarreau <w@1wt.eu> - 2017-05-16 07:30 +0200
      Re: CVE-2016-10229 in 4.4.x series Steven Pease <spease@suitabletech.com> - 2017-05-16 08:00 +0200
        Re: CVE-2016-10229 in 4.4.x series Willy Tarreau <w@1wt.eu> - 2017-05-16 08:10 +0200

#1642154 — CVE-2016-10229 in 4.4.x series

FromSteven Pease <spease@suitabletech.com>
Date2017-05-16 03:20 +0200
SubjectCVE-2016-10229 in 4.4.x series
Message-ID<tHzjA-7hu-9@gated-at.bofh.it>
Hi,

This is my first post - not currently subscribed so please CC me. :) I
searched a bit for this question, but couldn't find an answer (Googled
'2016-10229 site:lkml.org').

Does CVE-2016-10229 affect the newest version of the 4.4.x kernel
series (currently 4.4.68) and are there any plans to fix this in the
4.4 kernel series?

Thanks,

-- 
- Steven

[toc] | [next] | [standalone]


#1642217

FromWilly Tarreau <w@1wt.eu>
Date2017-05-16 07:30 +0200
Message-ID<tHDdw-1qC-13@gated-at.bofh.it>
In reply to#1642154
On Mon, May 15, 2017 at 06:09:53PM -0700, Steven Pease wrote:
> Hi,
> 
> This is my first post - not currently subscribed so please CC me. :) I
> searched a bit for this question, but couldn't find an answer (Googled
> '2016-10229 site:lkml.org').
> 
> Does CVE-2016-10229 affect the newest version of the 4.4.x kernel
> series (currently 4.4.68) and are there any plans to fix this in the
> 4.4 kernel series?

This one was fixed by upstream commit 197c949 ("udp: properly support
MSG_PEEK with truncated buffers"), which was backported in 4.4 as
commit dfe2042d96 in 4.4.21. So in short, 4.4.68 is safe.

Willy

[toc] | [prev] | [next] | [standalone]


#1642229

FromSteven Pease <spease@suitabletech.com>
Date2017-05-16 08:00 +0200
Message-ID<tHDGy-1Df-7@gated-at.bofh.it>
In reply to#1642217
Is there any particular reason that the CVE appears to be filed
against 4.4.60? Or is this just a mistake?

http://www.cvedetails.com/cve/CVE-2016-10229/

- Steven

On Mon, May 15, 2017 at 10:20 PM, Willy Tarreau <w@1wt.eu> wrote:
> On Mon, May 15, 2017 at 06:09:53PM -0700, Steven Pease wrote:
>> Hi,
>>
>> This is my first post - not currently subscribed so please CC me. :) I
>> searched a bit for this question, but couldn't find an answer (Googled
>> '2016-10229 site:lkml.org').
>>
>> Does CVE-2016-10229 affect the newest version of the 4.4.x kernel
>> series (currently 4.4.68) and are there any plans to fix this in the
>> 4.4 kernel series?
>
> This one was fixed by upstream commit 197c949 ("udp: properly support
> MSG_PEEK with truncated buffers"), which was backported in 4.4 as
> commit dfe2042d96 in 4.4.21. So in short, 4.4.68 is safe.
>
> Willy



-- 
- Steven

[toc] | [prev] | [next] | [standalone]


#1642232

FromWilly Tarreau <w@1wt.eu>
Date2017-05-16 08:10 +0200
Message-ID<tHDQd-1Wi-5@gated-at.bofh.it>
In reply to#1642229
On Mon, May 15, 2017 at 10:53:50PM -0700, Steven Pease wrote:
> Is there any particular reason that the CVE appears to be filed
> against 4.4.60? Or is this just a mistake?
> 
> http://www.cvedetails.com/cve/CVE-2016-10229/

I have no idea why. Maybe they mentionned the current version at the
moment the CVE was issued (which seems to match). In fact this bug was
discovered as being a vulnerability long after the bug was fixed.

Willy

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web