summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2022-08-09 20:04:22 +0200
committerSalvatore Bonaccorso <carnil@debian.org>2022-08-09 20:04:22 +0200
commit6f25fcaf3301727fece74ca5015cf214d80459c4 (patch)
treee3112de8482e03b34e43fdfce774d3acd3f12b08
parent8cabe1a88cdcbefadecc895b0b76ed22f1721885 (diff)
Mark CVE-2022-2590 as pending for sid
-rw-r--r--active/CVE-2022-25907
1 files changed, 6 insertions, 1 deletions
diff --git a/active/CVE-2022-2590 b/active/CVE-2022-2590
index c8aaf933..4764df14 100644
--- a/active/CVE-2022-2590
+++ b/active/CVE-2022-2590
@@ -5,10 +5,15 @@ References:
Notes:
carnil> Commit fixes 9ae0f87d009c ("mm/shmem: unconditionally set pte
carnil> dirty in mfill_atomic_install_pte") in 5.16-rc1.
+ carnil> David Hildenbrand reports that "Kernels before extended uffd-wp
+ carnil> support and before PageAnonExclusive (< 5.19) can simply revert
+ carnil> the problematic commit instead and be safe regarding
+ carnil> UFFDIO_CONTINUE. A backport to v5.19 requires minor adjustments
+ carnil> due to lack of vma_soft_dirty_enabled()."
Bugs:
upstream: needed
5.10-upstream-stable: N/A "Vulnerable code introduced later"
4.19-upstream-stable: N/A "Vulnerable code introduced later"
-sid: needed
+sid: pending (5.18.16-1) [bugfix/all/Revert-mm-shmem-unconditionally-set-pte-dirty-in-mfi.patch]
5.10-bullseye-security: N/A "Vulnerable code introduced later"
4.19-buster-security: N/A "Vulnerable code introduced later"

© 2014-2024 Faster IT GmbH | imprint | privacy policy