[kernel-sec-discuss] r4736 - active

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Nov 28 09:22:27 UTC 2016


Author: carnil
Date: 2016-11-28 09:22:27 +0000 (Mon, 28 Nov 2016)
New Revision: 4736

Added:
   active/CVE-2016-9178
Log:
Add CVE-2016-9178 to active list

Added: active/CVE-2016-9178
===================================================================
--- active/CVE-2016-9178	                        (rev 0)
+++ active/CVE-2016-9178	2016-11-28 09:22:27 UTC (rev 4736)
@@ -0,0 +1,16 @@
+Description: minor information leak in get_user_ex()
+References:
+Notes:
+ carnil> If this issue is fixed, then one needs to assure
+ carnil> to not introduce the privilege escalation issue
+ carnil> as present in 4.4.22 through 4.4.28 (cf.
+ carnil> CVE-2016-9644) due to a wrong backport/missing
+ carnil> backport of 548acf19234dbda5a52d5a8e7e205af46e9da840
+ carnil> as well. See notes in CVE-2016-9644
+Bugs:
+upstream: released (4.8-rc7) [1c109fabbd51863475cd12ac206bdd249aee35af]
+3.16-upstream-stable:
+3.2-upstream-stable:
+sid: released (4.7.5-1)
+3.16-jessie-security:
+3.2-wheezy-security:




More information about the kernel-sec-discuss mailing list