[kernel-sec-discuss] r5446 - active

Salvatore Bonaccorso carnil at moszumanska.debian.org
Thu Aug 3 14:28:43 UTC 2017


Author: carnil
Date: 2017-08-03 14:28:42 +0000 (Thu, 03 Aug 2017)
New Revision: 5446

Added:
   active/CVE-2017-7533
Log:
Add CVE-2017-7533

Added: active/CVE-2017-7533
===================================================================
--- active/CVE-2017-7533	                        (rev 0)
+++ active/CVE-2017-7533	2017-08-03 14:28:42 UTC (rev 5446)
@@ -0,0 +1,15 @@
+Description: Race condition between notify_handle_event() and sys_rename()
+References:
+ https://patchwork.kernel.org/patch/9755753/
+ https://patchwork.kernel.org/patch/9755757/
+Notes:
+ carnil> Introduced by 7053aee26a3548ebaba046ae2e52396ccf56ac6c in v3.14-rc1
+Bugs:
+upstream: released (4.13-rc1) [49d31c2f389acfe83417083e1208422b4091cd9e]
+4.9-upstream-stable: needed
+3.16-upstream-stable: needed
+3.2-upstream-stable: N/A "Vulnerable code introduced in (3.14-rc1) [7053aee26a3548ebaba046ae2e52396ccf56ac6c]"
+sid: needed
+4.9-stretch-security: needed
+3.16-jessie-security: needed
+3.2-wheezy-security: N/A "Vulnerable code not present"




More information about the kernel-sec-discuss mailing list