[kernel-sec-discuss] r5485 - active

Ben Hutchings benh at moszumanska.debian.org
Thu Aug 17 20:33:06 UTC 2017


Author: benh
Date: 2017-08-17 20:33:05 +0000 (Thu, 17 Aug 2017)
New Revision: 5485

Modified:
   active/CVE-2017-1000363
   active/CVE-2017-1000365
   active/CVE-2017-10911
   active/CVE-2017-11176
   active/CVE-2017-7482
   active/CVE-2017-7542
   active/CVE-2017-7889
Log:
Mark issues pending for wheezy

Modified: active/CVE-2017-1000363
===================================================================
--- active/CVE-2017-1000363	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-1000363	2017-08-17 20:33:05 UTC (rev 5485)
@@ -9,4 +9,4 @@
 sid: released (4.9.30-1)
 4.9-stretch-security: N/A "Fixed before branching point"
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/all/char-lp-fix-possible-integer-overflow-in-lp_setup.patch]
-3.2-wheezy-security: needed
+3.2-wheezy-security: pending (3.2.91-1)

Modified: active/CVE-2017-1000365
===================================================================
--- active/CVE-2017-1000365	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-1000365	2017-08-17 20:33:05 UTC (rev 5485)
@@ -11,4 +11,4 @@
 sid: released (4.11.11-1)
 4.9-stretch-security: released (4.9.30-2+deb9u3) [bugfix/all/fs-exec.c-account-for-argv-envp-pointers.patch]
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/all/fs-exec.c-account-for-argv-envp-pointers.patch]
-3.2-wheezy-security: needed
+3.2-wheezy-security: pending (3.2.91-1)

Modified: active/CVE-2017-10911
===================================================================
--- active/CVE-2017-10911	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-10911	2017-08-17 20:33:05 UTC (rev 5485)
@@ -10,4 +10,4 @@
 sid: released (4.11.11-1)
 4.9-stretch-security: released (4.9.30-2+deb9u3) [bugfix/all/xen-blkback-don-t-leak-stack-data-via-response-ring.patch]
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/all/xen-blkback-don-t-leak-stack-data-via-response-ring.patch]
-3.2-wheezy-security: needed
+3.2-wheezy-security: pending (3.2.91-1)

Modified: active/CVE-2017-11176
===================================================================
--- active/CVE-2017-11176	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-11176	2017-08-17 20:33:05 UTC (rev 5485)
@@ -11,4 +11,4 @@
 sid: released (4.11.11-1)
 4.9-stretch-security: released (4.9.30-2+deb9u3) [bugfix/all/mqueue-fix-a-use-after-free-in-sys_mq_notify.patch]
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/all/mqueue-fix-a-use-after-free-in-sys_mq_notify.patch]
-3.2-wheezy-security: needed
+3.2-wheezy-security: pending (3.2.91-1) [bugfix/all/mqueue-fix-a-use-after-free-in-sys_mq_notify.patch]

Modified: active/CVE-2017-7482
===================================================================
--- active/CVE-2017-7482	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-7482	2017-08-17 20:33:05 UTC (rev 5485)
@@ -12,4 +12,4 @@
 sid: released (4.11.11-1)
 4.9-stretch-security: released (4.9.30-2+deb9u3) [bugfix/all/rxrpc-Fix-several-cases-where-a-padded-len-isn-t-che.patch]
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/all/rxrpc-Fix-several-cases-where-a-padded-len-isn-t-che.patch]
-3.2-wheezy-security: pending (3.2.90-1)
+3.2-wheezy-security: pending (3.2.91-1)

Modified: active/CVE-2017-7542
===================================================================
--- active/CVE-2017-7542	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-7542	2017-08-17 20:33:05 UTC (rev 5485)
@@ -9,4 +9,4 @@
 sid: released (4.12.6-1)
 4.9-stretch-security: released (4.9.30-2+deb9u3) [bugfix/all/ipv6-avoid-overflow-of-offset-in-ip6_find_1stfragopt.patch]
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/all/ipv6-avoid-overflow-of-offset-in-ip6_find_1stfragopt.patch]
-3.2-wheezy-security: needed
+3.2-wheezy-security: pending (3.2.91-1) [bugfix/all/ipv6-avoid-overflow-of-offset-in-ip6_find_1stfragopt.patch]

Modified: active/CVE-2017-7889
===================================================================
--- active/CVE-2017-7889	2017-08-17 20:25:35 UTC (rev 5484)
+++ active/CVE-2017-7889	2017-08-17 20:33:05 UTC (rev 5485)
@@ -14,4 +14,4 @@
 sid: released (4.9.25-1)
 4.9-stretch-security: N/A "Fixed before branching point"
 3.16-jessie-security: released (3.16.43-2+deb8u3) [bugfix/x86/mm-Tighten-x86-dev-mem-with-zeroing-reads.patch b/debian/patches/bugfix/x86/mm-Tighten-x86-dev-mem-with-zeroing-reads.patch]
-3.2-wheezy-security: needed
+3.2-wheezy-security: pending (3.2.91-1)




More information about the kernel-sec-discuss mailing list