[kernel] r12742 - in dists/etch-security/linux-2.6.24/debian: . patches/bugfix/all patches/series

Dann Frazier dannf at alioth.debian.org
Tue Feb 10 05:52:34 UTC 2009


Author: dannf
Date: Tue Feb 10 05:52:32 2009
New Revision: 12742

Log:
security: introduce missing kfree (CVE-2009-0031)

Added:
   dists/etch-security/linux-2.6.24/debian/patches/bugfix/all/security-keyctl-missing-kfree.patch   (contents, props changed)
      - copied, changed from r12739, /dists/sid/linux-2.6/debian/patches/bugfix/all/security-keyctl-missing-kfree.patch
Modified:
   dists/etch-security/linux-2.6.24/debian/changelog
   dists/etch-security/linux-2.6.24/debian/patches/series/6~etchnhalf.8etch1

Modified: dists/etch-security/linux-2.6.24/debian/changelog
==============================================================================
--- dists/etch-security/linux-2.6.24/debian/changelog	(original)
+++ dists/etch-security/linux-2.6.24/debian/changelog	Tue Feb 10 05:52:32 2009
@@ -9,8 +9,9 @@
   * nfs: Fix fcntl/close race (CVE-2008-4307)
   * Fix sign-extend ABI issue w/ system calls on various 64-bit architectures
     (CVE-2009-0029)
+  * security: introduce missing kfree (CVE-2009-0031)
 
- -- dann frazier <dannf at debian.org>  Wed, 21 Jan 2009 01:35:50 -0700
+ -- dann frazier <dannf at debian.org>  Mon, 09 Feb 2009 22:49:26 -0700
 
 linux-2.6.24 (2.6.24-6~etchnhalf.8) stable; urgency=high
 

Copied: dists/etch-security/linux-2.6.24/debian/patches/bugfix/all/security-keyctl-missing-kfree.patch (from r12739, /dists/sid/linux-2.6/debian/patches/bugfix/all/security-keyctl-missing-kfree.patch)
==============================================================================
--- /dists/sid/linux-2.6/debian/patches/bugfix/all/security-keyctl-missing-kfree.patch	(original)
+++ dists/etch-security/linux-2.6.24/debian/patches/bugfix/all/security-keyctl-missing-kfree.patch	Tue Feb 10 05:52:32 2009
@@ -12,11 +12,12 @@
     Signed-off-by: Vegard Nossum <vegard.nossum at gmail.com>
     Signed-off-by: Linus Torvalds <torvalds at linux-foundation.org>
 
-diff --git a/security/keys/keyctl.c b/security/keys/keyctl.c
-index e9335e1..b1ec3b4 100644
---- a/security/keys/keyctl.c
-+++ b/security/keys/keyctl.c
-@@ -270,6 +270,7 @@ long keyctl_join_session_keyring(const char __user *_name)
+Adjusted to apply to Debian's 2.6.24 by dann frazier <dannf at debian.org>
+
+diff -urpN linux-source-2.6.24.orig/security/keys/keyctl.c linux-source-2.6.24/security/keys/keyctl.c
+--- linux-source-2.6.24.orig/security/keys/keyctl.c	2008-01-24 15:58:37.000000000 -0700
++++ linux-source-2.6.24/security/keys/keyctl.c	2009-02-09 22:43:52.000000000 -0700
+@@ -253,6 +253,7 @@ long keyctl_join_session_keyring(const c
  
  	/* join the session */
  	ret = join_session_keyring(name);

Modified: dists/etch-security/linux-2.6.24/debian/patches/series/6~etchnhalf.8etch1
==============================================================================
--- dists/etch-security/linux-2.6.24/debian/patches/series/6~etchnhalf.8etch1	(original)
+++ dists/etch-security/linux-2.6.24/debian/patches/series/6~etchnhalf.8etch1	Tue Feb 10 05:52:32 2009
@@ -55,3 +55,4 @@
 + bugfix/all/CVE-2009-0029/0043pre1-missing-include.patch
 + bugfix/all/CVE-2009-0029/0043-System-call-wrappers-part-33.patch
 + bugfix/all/CVE-2009-0029/0044-s390-specific-system-call-wrappers.patch
++ bugfix/all/security-keyctl-missing-kfree.patch



More information about the Kernel-svn-changes mailing list