FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Ubuntu > Ubuntu Kernel Team

 
 
LinkBack Thread Tools
 
Old 07-21-2011, 08:20 PM
Tim Gardner
 
Default APPLIED: dccp: fix oops on Reset after close

On 07/21/2011 06:59 AM, Andy Whitcroft wrote:

CVE-2011-1093
The dccp_rcv_state_process function in net/dccp/input.c in the
Datagram Congestion Control Protocol (DCCP) implementation in
the Linux kernel before 2.6.38 does not properly handle packets
for a CLOSED endpoint, which allows remote attackers to cause a
denial of service (NULL pointer dereference and OOPS) by sending
a DCCP-Close packet followed by a DCCP-Reset packet.

The fix for this has hit lucid and later via mainline and stable.
Following this are two patches, the first for hardy, the second for
lucid/fsl-imx51 and maverick/ti-omap4. I all cases they are a simple
cherry-pick from the mainline commit as applied to the existing branches;
hardy differs in context only.

Proposing for hardy, lucid/fsl-imx51 and maverick/ti-omap4.

-apw




--
Tim Gardner tim.gardner@canonical.com

--
kernel-team mailing list
kernel-team@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/kernel-team
 

Thread Tools




All times are GMT. The time now is 09:08 PM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org