[kernel-sec-discuss] r4629 - active

Salvatore Bonaccorso carnil at moszumanska.debian.org
Mon Oct 10 17:48:20 UTC 2016


Author: carnil
Date: 2016-10-10 17:48:20 +0000 (Mon, 10 Oct 2016)
New Revision: 4629

Added:
   active/CVE-2016-7039
Log:
Add CVE-2016-7039

Added: active/CVE-2016-7039
===================================================================
--- active/CVE-2016-7039	                        (rev 0)
+++ active/CVE-2016-7039	2016-10-10 17:48:20 UTC (rev 4629)
@@ -0,0 +1,14 @@
+Description: net: unbounded recursion in the vlan GRO processing
+References:
+ https://www.mail-archive.com/netdev%40vger.kernel.org/msg132064.html
+Notes:
+ carnil> Note the break-fix fac8e0f579695a3ecbc4d3cac369139d7f819971
+ carnil> will need a separate CVE ID and is in the process of beeing
+ carnil> assigned.
+Bugs:
+upstream: needed
+3.16-upstream-stable: N/A "Vulnerable code introduced with 9b174d88c257150562b0101fcc6cb6c3cb74275c and 66e5133f19e901a044fa5eaeeb6ecff4545839e5"
+3.2-upstream-stable: N/A "Vulnerable code introduced with 9b174d88c257150562b0101fcc6cb6c3cb74275c and 66e5133f19e901a044fa5eaeeb6ecff4545839e5"
+sid: needed
+3.16-jessie-security: N/A "Vulnerable code not present"
+3.2-wheezy-security: N/A "Vulnerable code not present"




More information about the kernel-sec-discuss mailing list