[kernel-sec-discuss] r1943 - active retired

Moritz Muehlenhoff jmm at alioth.debian.org
Wed Sep 1 09:33:59 UTC 2010


Author: jmm
Date: 2010-09-01 09:33:54 +0000 (Wed, 01 Sep 2010)
New Revision: 1943

Added:
   retired/CVE-2010-2066
   retired/CVE-2010-2538
Removed:
   active/CVE-2010-2066
   active/CVE-2010-2538
Log:
retire issues


Deleted: active/CVE-2010-2066
===================================================================
--- active/CVE-2010-2066	2010-09-01 09:30:15 UTC (rev 1942)
+++ active/CVE-2010-2066	2010-09-01 09:33:54 UTC (rev 1943)
@@ -1,14 +0,0 @@
-Candidate: CVE-2010-2066
-Description:
-References:
- http://git.kernel.org/linus/1f5a81e41f8b1a782c68d3843e9ec1bfaadf7d72
- https://bugzilla.redhat.com/show_bug.cgi?id=601006
-Notes:
- jmm> Submitted for stable
- jmm> Introduced in 2.6.31
-Bugs:
-upstream: released (2.6.35-rc2)
-2.6.32-upstream-stable: released (2.6.32.19) [c60ca62]
-linux-2.6: released (2.6.32-21) [bugfix/all/stable/2.6.32.19.patch]
-2.6.26-lenny-security: N/A
-2.6.32-squeeze-security: released (2.6.32-21) [bugfix/all/stable/2.6.32.19.patch]

Deleted: active/CVE-2010-2538
===================================================================
--- active/CVE-2010-2538	2010-09-01 09:30:15 UTC (rev 1942)
+++ active/CVE-2010-2538	2010-09-01 09:33:54 UTC (rev 1943)
@@ -1,14 +0,0 @@
-Candidate: CVE-2010-2538
-Description:
- The BTRFS_IOC_CLONE_RANGE ioctl was subject to an integer overflow
- in specifying offsets to copy from a file, which potentially allows a
- local user to read sensitive filesystem data.
-References:
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2ebc3464781ad24474abcbd2274e6254689853b5
-Notes:
-Bugs:
-upstream: released (2.6.35)
-2.6.32-upstream-stable: released (2.6.32.17) [8875b99]
-linux-2.6: released (2.6.32-19) [bugfix/all/stable/2.6.32.17.patch]
-2.6.26-lenny-security: N/A "no btrfs"
-2.6.32-squeeze-security: released (2.6.32-19) [bugfix/all/stable/2.6.32.17.patch]

Copied: retired/CVE-2010-2066 (from rev 1942, active/CVE-2010-2066)
===================================================================
--- retired/CVE-2010-2066	                        (rev 0)
+++ retired/CVE-2010-2066	2010-09-01 09:33:54 UTC (rev 1943)
@@ -0,0 +1,14 @@
+Candidate: CVE-2010-2066
+Description:
+References:
+ http://git.kernel.org/linus/1f5a81e41f8b1a782c68d3843e9ec1bfaadf7d72
+ https://bugzilla.redhat.com/show_bug.cgi?id=601006
+Notes:
+ jmm> Submitted for stable
+ jmm> Introduced in 2.6.31
+Bugs:
+upstream: released (2.6.35-rc2)
+2.6.32-upstream-stable: released (2.6.32.19) [c60ca62]
+linux-2.6: released (2.6.32-21) [bugfix/all/stable/2.6.32.19.patch]
+2.6.26-lenny-security: N/A
+2.6.32-squeeze-security: released (2.6.32-21) [bugfix/all/stable/2.6.32.19.patch]


Property changes on: retired/CVE-2010-2066
___________________________________________________________________
Added: svn:mergeinfo
   + 

Copied: retired/CVE-2010-2538 (from rev 1940, active/CVE-2010-2538)
===================================================================
--- retired/CVE-2010-2538	                        (rev 0)
+++ retired/CVE-2010-2538	2010-09-01 09:33:54 UTC (rev 1943)
@@ -0,0 +1,14 @@
+Candidate: CVE-2010-2538
+Description:
+ The BTRFS_IOC_CLONE_RANGE ioctl was subject to an integer overflow
+ in specifying offsets to copy from a file, which potentially allows a
+ local user to read sensitive filesystem data.
+References:
+ http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2ebc3464781ad24474abcbd2274e6254689853b5
+Notes:
+Bugs:
+upstream: released (2.6.35)
+2.6.32-upstream-stable: released (2.6.32.17) [8875b99]
+linux-2.6: released (2.6.32-19) [bugfix/all/stable/2.6.32.17.patch]
+2.6.26-lenny-security: N/A "no btrfs"
+2.6.32-squeeze-security: released (2.6.32-19) [bugfix/all/stable/2.6.32.17.patch]


Property changes on: retired/CVE-2010-2538
___________________________________________________________________
Added: svn:mergeinfo
   + 




More information about the kernel-sec-discuss mailing list