[kernel-sec-discuss] r4690 - active retired

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sun Nov 6 16:30:41 UTC 2016


Author: carnil
Date: 2016-11-06 16:30:32 +0000 (Sun, 06 Nov 2016)
New Revision: 4690

Added:
   retired/CVE-2016-7039
Removed:
   active/CVE-2016-7039
Log:
Retire CVE-2016-7039

Deleted: active/CVE-2016-7039
===================================================================
--- active/CVE-2016-7039	2016-11-06 16:22:25 UTC (rev 4689)
+++ active/CVE-2016-7039	2016-11-06 16:30:32 UTC (rev 4690)
@@ -1,14 +0,0 @@
-Description: net: unbounded recursion in the vlan GRO processing
-References:
- https://www.mail-archive.com/netdev%40vger.kernel.org/msg132064.html
- https://patchwork.ozlabs.org/patch/680412/
-Notes:
- carnil> Note the break-fix fac8e0f579695a3ecbc4d3cac369139d7f819971
- carnil> got assigned a separate CVE ID, CVE-2016-8666
-Bugs:
-upstream: released (4.9-rc4) [fcd91dd449867c6bfe56a81cabba76b829fd05cd]
-3.16-upstream-stable: N/A "Vulnerable code introduced with 9b174d88c257150562b0101fcc6cb6c3cb74275c and 66e5133f19e901a044fa5eaeeb6ecff4545839e5"
-3.2-upstream-stable: N/A "Vulnerable code introduced with 9b174d88c257150562b0101fcc6cb6c3cb74275c and 66e5133f19e901a044fa5eaeeb6ecff4545839e5"
-sid: released (4.7.8-1) [bugfix/all/net-add-recursion-limit-to-gro.patch]
-3.16-jessie-security: N/A "Vulnerable code not present"
-3.2-wheezy-security: N/A "Vulnerable code not present"

Copied: retired/CVE-2016-7039 (from rev 4689, active/CVE-2016-7039)
===================================================================
--- retired/CVE-2016-7039	                        (rev 0)
+++ retired/CVE-2016-7039	2016-11-06 16:30:32 UTC (rev 4690)
@@ -0,0 +1,14 @@
+Description: net: unbounded recursion in the vlan GRO processing
+References:
+ https://www.mail-archive.com/netdev%40vger.kernel.org/msg132064.html
+ https://patchwork.ozlabs.org/patch/680412/
+Notes:
+ carnil> Note the break-fix fac8e0f579695a3ecbc4d3cac369139d7f819971
+ carnil> got assigned a separate CVE ID, CVE-2016-8666
+Bugs:
+upstream: released (4.9-rc4) [fcd91dd449867c6bfe56a81cabba76b829fd05cd]
+3.16-upstream-stable: N/A "Vulnerable code introduced with 9b174d88c257150562b0101fcc6cb6c3cb74275c and 66e5133f19e901a044fa5eaeeb6ecff4545839e5"
+3.2-upstream-stable: N/A "Vulnerable code introduced with 9b174d88c257150562b0101fcc6cb6c3cb74275c and 66e5133f19e901a044fa5eaeeb6ecff4545839e5"
+sid: released (4.7.8-1) [bugfix/all/net-add-recursion-limit-to-gro.patch]
+3.16-jessie-security: N/A "Vulnerable code not present"
+3.2-wheezy-security: N/A "Vulnerable code not present"




More information about the kernel-sec-discuss mailing list