[kernel-sec-discuss] r5628 - active

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Oct 10 04:38:12 UTC 2017


Author: carnil
Date: 2017-10-10 04:38:12 +0000 (Tue, 10 Oct 2017)
New Revision: 5628

Added:
   active/CVE-2017-1000255
Log:
Add CVE-2017-1000255

Added: active/CVE-2017-1000255
===================================================================
--- active/CVE-2017-1000255	                        (rev 0)
+++ active/CVE-2017-1000255	2017-10-10 04:38:12 UTC (rev 5628)
@@ -0,0 +1,18 @@
+Description: powerpc/64s: Use emergency stack for kernel TM Bad Thing program checks
+References:
+Notes:
+ carnil> Introduced in 4.9-rc1 with 5d176f751ee3c6eededd984ad409bff201f436a7
+ carnil> Kernels built with CONFIG_PPC_TRANSACTIONAL_MEM=n are not vulnerable.
+ carnil> Fix will require two patches:
+ carnil> "powerpc/64s: Use emergency stack for kernel TM Bad Thing program checks"
+ carnil> and
+ carnil> "powerpc/tm: Fix illegal TM state in signal handler"
+Bugs:
+upstream: needed
+4.9-upstream-stable: needed
+3.16-upstream-stable: N/A "Vulnerable code introduced in 4.9-rc1 with 5d176f751ee3c6eededd984ad409bff201f436a7"
+3.2-upstream-stable: N/A "Vulnerable code introduced in 4.9-rc1 with 5d176f751ee3c6eededd984ad409bff201f436a7"
+sid: needed
+4.9-stretch-security: needed
+3.16-jessie-security: N/A "Vulerable code introduced later"
+3.2-wheezy-security: N/A "Vulerable code introduced later"




More information about the kernel-sec-discuss mailing list