[kernel-sec-discuss] r5414 - active

Ben Hutchings benh at moszumanska.debian.org
Sat Jul 15 12:44:38 UTC 2017


Author: benh
Date: 2017-07-15 12:44:38 +0000 (Sat, 15 Jul 2017)
New Revision: 5414

Modified:
   active/CVE-2017-10810
   active/CVE-2017-11176
Log:
Fill in status of two issues

Modified: active/CVE-2017-10810
===================================================================
--- active/CVE-2017-10810	2017-07-13 16:06:04 UTC (rev 5413)
+++ active/CVE-2017-10810	2017-07-15 12:44:38 UTC (rev 5414)
@@ -4,9 +4,9 @@
 Bugs:
 upstream: released (4.12-rc1) [385aee965b4e4c36551c362a334378d2985b722a]
 4.9-upstream-stable: released (4.9.37) [366d9207d9e002bf1a6d9da13a7f8f85b8a40c0b]
-3.16-upstream-stable:
-3.2-upstream-stable:
+3.16-upstream-stable: N/A "Vulnerable code not present"
+3.2-upstream-stable: N/A "Vulnerable code not present"
 sid: needed
 4.9-stretch-security: needed
-3.16-jessie-security:
-3.2-wheezy-security:
+3.16-jessie-security: N/A "Vulnerable code not present"
+3.2-wheezy-security: N/A "Vulnerable code not present"

Modified: active/CVE-2017-11176
===================================================================
--- active/CVE-2017-11176	2017-07-13 16:06:04 UTC (rev 5413)
+++ active/CVE-2017-11176	2017-07-15 12:44:38 UTC (rev 5414)
@@ -1,12 +1,14 @@
 Description: mqueue: fix a use-after-free in sys_mq_notify()
 References:
 Notes:
+ bwh> Introduced pre-git by "posix message queues: send notifications via
+ bwh> netlink" in 2.6.6
 Bugs:
 upstream: pending [f991af3daabaecff34684fd51fac80319d1baad1]
-4.9-upstream-stable:
-3.16-upstream-stable:
-3.2-upstream-stable:
-sid:
-4.9-stretch-security:
-3.16-jessie-security:
-3.2-wheezy-security:
+4.9-upstream-stable: needed
+3.16-upstream-stable: needed
+3.2-upstream-stable: needed
+sid: needed
+4.9-stretch-security: needed
+3.16-jessie-security: needed
+3.2-wheezy-security: needed




More information about the kernel-sec-discuss mailing list