[kernel-sec-discuss] r3755 - active

Ben Hutchings benh at moszumanska.debian.org
Fri Apr 24 15:00:45 UTC 2015


Author: benh
Date: 2015-04-24 15:00:44 +0000 (Fri, 24 Apr 2015)
New Revision: 3755

Modified:
   active/CVE-2014-8171
Log:
Mark CVE-2014-8171 fixed in sid, likely unfixable in squeeze and wheezy

Modified: active/CVE-2014-8171
===================================================================
--- active/CVE-2014-8171	2015-04-24 14:41:52 UTC (rev 3754)
+++ active/CVE-2014-8171	2015-04-24 15:00:44 UTC (rev 3755)
@@ -1,12 +1,14 @@
 Description: memcg: OOM handling DoS
 References:
 Notes:
+ bwh> We require a kernel parameter to enable memcg, so most systems should
+ bwh> not be affected.
 Bugs:
 upstream: released (v3.12-rc1) [3812c8c8f3953921ef18544110dafc3505c1ac62], (v3.12-rc6) [4942642080ea82d99ab5b653abb9a12b7ba31f4a]
 2.6.32-upstream-stable:
-sid:
+sid: released (3.12.6-1)
 3.16-jessie-security: N/A "Fixed before initial release"
-3.2-wheezy-security:
-2.6.32-squeeze-security:
+3.2-wheezy-security: ignored "Too difficult and risky to backport"
+2.6.32-squeeze-security: ignored "Too difficult and risky to backport"
 3.16-upstream-stable: N/A "Fixed before initial release"
 3.2-upstream-stable:




More information about the kernel-sec-discuss mailing list