[kernel-sec-discuss] r5235 - active

Ben Hutchings benh at moszumanska.debian.org
Thu Apr 27 19:29:03 UTC 2017


Author: benh
Date: 2017-04-27 19:29:03 +0000 (Thu, 27 Apr 2017)
New Revision: 5235

Modified:
   active/CVE-2017-7618
Log:
Note bug that needs to be fixed along with CVE-2017-7618

Modified: active/CVE-2017-7618
===================================================================
--- active/CVE-2017-7618	2017-04-27 18:45:29 UTC (rev 5234)
+++ active/CVE-2017-7618	2017-04-27 19:29:03 UTC (rev 5235)
@@ -4,7 +4,9 @@
  https://git.kernel.org/pub/scm/linux/kernel/git/herbert/crypto-2.6.git/commit/?id=ef0579b64e93188710d48667cb5e014926af9f1b
 Notes:
  bwh> This depends on several earlier fixes to crypto/ahash.c, applied
- bwh> between 3.2 and 3.16.
+ bwh> between 3.2 and 3.16.  It also breaks algif_aead, fixed by commit
+ bwh> e6534aebb26e ("crypto: algif_aead - Fix bogus request dereference in
+ bwh> completion function").
 Bugs:
 upstream: released (4.11-rc8) [ef0579b64e93188710d48667cb5e014926af9f1b]
 4.9-upstream-stable: released (4.9.24) [c10479591869177ae7ac0570b54ace6fbdeb57c2]




More information about the kernel-sec-discuss mailing list