[kernel-sec-discuss] r5186 - active retired

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Apr 21 15:32:34 UTC 2017


Author: carnil
Date: 2017-04-21 15:32:34 +0000 (Fri, 21 Apr 2017)
New Revision: 5186

Added:
   retired/CVE-2017-6353
Removed:
   active/CVE-2017-6353
Log:
Retire CVE-2017-6353

Deleted: active/CVE-2017-6353
===================================================================
--- active/CVE-2017-6353	2017-04-21 15:30:03 UTC (rev 5185)
+++ active/CVE-2017-6353	2017-04-21 15:32:34 UTC (rev 5186)
@@ -1,17 +0,0 @@
-Description: sctp: deny peeloff operation on asocs with threads sleeping on it
-References:
- https://marc.info/?l=linux-netdev&m=148785309416337&w=2
-Notes:
- carnil> "technically" 3.2-wheezy-security and 3.16-jessie-security are not
- carnil> affected since we did not apply 2dcab598484185dea7ec22219c76dcdd59e3cb90
- carnil> but maybe we want to make an exception here and threat this CVE never-
- carnil> theless as affected for all branches.
- bwh> Introduced by attempted fix for CVE-2017-5986
-Bugs:
-upstream: released (4.11-rc1) [dfcb9f4f99f1e9a49e43398a7bfbf56927544af1]
-4.9-upstream-stable: released (4.9.24) [35b9d61ea910c1ebd4652b32cc7d713f6689b4f4]
-3.16-upstream-stable: released (3.16.42) [sctp-deny-peeloff-operation-on-asocs-with-threads-sleeping-on-it.patch]
-3.2-upstream-stable: released (3.2.87) [sctp-deny-peeloff-operation-on-asocs-with-threads-sleeping-on-it.patch]
-sid: released (4.9.13-1) [bugfix/all/sctp-deny-peeloff-operation-on-asocs-with-threads-sl.patch]
-3.16-jessie-security: released (3.16.39-1+deb8u2) [bugfix/all/sctp-deny-peeloff-operation-on-asocs-with-threads-sl.patch]
-3.2-wheezy-security: released (3.2.86-1) [bugfix/all/sctp-deny-peeloff-operation-on-asocs-with-threads-sleeping-on-it.patch]

Copied: retired/CVE-2017-6353 (from rev 5185, active/CVE-2017-6353)
===================================================================
--- retired/CVE-2017-6353	                        (rev 0)
+++ retired/CVE-2017-6353	2017-04-21 15:32:34 UTC (rev 5186)
@@ -0,0 +1,17 @@
+Description: sctp: deny peeloff operation on asocs with threads sleeping on it
+References:
+ https://marc.info/?l=linux-netdev&m=148785309416337&w=2
+Notes:
+ carnil> "technically" 3.2-wheezy-security and 3.16-jessie-security are not
+ carnil> affected since we did not apply 2dcab598484185dea7ec22219c76dcdd59e3cb90
+ carnil> but maybe we want to make an exception here and threat this CVE never-
+ carnil> theless as affected for all branches.
+ bwh> Introduced by attempted fix for CVE-2017-5986
+Bugs:
+upstream: released (4.11-rc1) [dfcb9f4f99f1e9a49e43398a7bfbf56927544af1]
+4.9-upstream-stable: released (4.9.24) [35b9d61ea910c1ebd4652b32cc7d713f6689b4f4]
+3.16-upstream-stable: released (3.16.42) [sctp-deny-peeloff-operation-on-asocs-with-threads-sleeping-on-it.patch]
+3.2-upstream-stable: released (3.2.87) [sctp-deny-peeloff-operation-on-asocs-with-threads-sleeping-on-it.patch]
+sid: released (4.9.13-1) [bugfix/all/sctp-deny-peeloff-operation-on-asocs-with-threads-sl.patch]
+3.16-jessie-security: released (3.16.39-1+deb8u2) [bugfix/all/sctp-deny-peeloff-operation-on-asocs-with-threads-sl.patch]
+3.2-wheezy-security: released (3.2.86-1) [bugfix/all/sctp-deny-peeloff-operation-on-asocs-with-threads-sleeping-on-it.patch]




More information about the kernel-sec-discuss mailing list