summaryrefslogtreecommitdiffstats
path: root/active
diff options
context:
space:
mode:
authordann frazier <dannf@debian.org>2010-08-29 20:09:40 +0000
committerdann frazier <dannf@debian.org>2010-08-29 20:09:40 +0000
commit05ef0adcd5bb7a0581bfdc10b35e3c6a1c1783b8 (patch)
tree2b2b17c954ae33e40d17499c597a2ebff6cfb3af /active
parentb2e97a192d476c6e2b635ad400bc6a5e596811d8 (diff)
various status updates
git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@1939 e094ebfe-e918-0410-adfb-c712417f3574
Diffstat (limited to 'active')
-rw-r--r--active/CVE-2010-224011
-rw-r--r--active/CVE-2010-25242
-rw-r--r--active/CVE-2010-29424
-rw-r--r--active/CVE-2010-29432
-rw-r--r--active/CVE-2010-29462
5 files changed, 11 insertions, 10 deletions
diff --git a/active/CVE-2010-2240 b/active/CVE-2010-2240
index d0cc1e36b..e6748e0cf 100644
--- a/active/CVE-2010-2240
+++ b/active/CVE-2010-2240
@@ -5,9 +5,10 @@ Notes:
jmm> 2.6.32.20 should have all the fixes, the missing ones compared to the patches used for
jmm> Lenny were merged in 2008 (7c88db0cb589df980acfb2f73c3595a0653004ec)
jmm> and 2009 (05fa199d45c54a9bda7aa3ae6537253d6f097aa9)
+ dannf> additional fix needed for hppa/ia64
Bugs:
-upstream: pending (2.6.36-rc1) [320b2b8, 528f913, 9605456, 05fa199]
-2.6.32-upstream-stable: released (2.6.32.20)
-linux-2.6: released (2.6.32-21) [bugfix/all/stable/2.6.32.19.patch]
-2.6.26-lenny-security: pending (2.6.26-24lenny1) [bugfix/all/mm-keep-a-guard-page-below-a-grow-down-stack-segment.patch, bugfix/all/mm-fix-missing-page-table-unmap-for-stack-guard-page-failure-case.patch, bugfix/x86/dont-send-SIGBUS-for-kernel-page-faults.patch, bugfix/all/mm-pass-correct-mm-when-growing-stack.patch, bugfix/all/mm-fix-page-table-unmap-for-stack-guard-page-properly.patch, bugfix/all/proc-fix-vma-display-mismatch-between-proc-pid-maps-smaps.patch, bugfix/all/mm-fix-up-some-user-visible-effects-of-the-stack-guard-page.patch]
-2.6.32-squeeze-security: pending (2.6.32-21) [bugfix/all/stable/2.6.32.20.patch]
+upstream: pending (2.6.36-rc3) [320b2b8, 528f913, 9605456, 05fa199, 8ca3eb0]
+2.6.32-upstream-stable: needed "2.6.32.y still needs 8ca3eb0"
+linux-2.6: needed "needs 8ca3eb0"
+2.6.26-lenny-security: pending (2.6.26-25) [bugfix/all/mm-keep-a-guard-page-below-a-grow-down-stack-segment.patch, bugfix/all/mm-fix-missing-page-table-unmap-for-stack-guard-page-failure-case.patch, bugfix/x86/dont-send-SIGBUS-for-kernel-page-faults.patch, bugfix/all/mm-pass-correct-mm-when-growing-stack.patch, bugfix/all/mm-fix-page-table-unmap-for-stack-guard-page-properly.patch, bugfix/all/proc-fix-vma-display-mismatch-between-proc-pid-maps-smaps.patch, bugfix/all/mm-fix-up-some-user-visible-effects-of-the-stack-guard-page.patch, bugfix/all/guard-page-for-stacks-that-grow-upwards.patch]
+2.6.32-squeeze-security: needed "needs 8ca3eb0"
diff --git a/active/CVE-2010-2524 b/active/CVE-2010-2524
index 437089d82..c4c2ee95a 100644
--- a/active/CVE-2010-2524
+++ b/active/CVE-2010-2524
@@ -9,5 +9,5 @@ Bugs:
upstream: released (2.6.35)
2.6.32-upstream-stable: released (2.6.32.17) [4ff7ffd]
linux-2.6: released (2.6.32-19) [bugfix/all/stable/2.6.32.17.patch]
-2.6.26-lenny-security: needed
+2.6.26-lenny-security: needed "needs port - upstream patch depends on newer key api"
2.6.32-squeeze-security: released (2.6.32-19) [bugfix/all/stable/2.6.32.17.patch]
diff --git a/active/CVE-2010-2942 b/active/CVE-2010-2942
index 2e127a957..6fd7fca88 100644
--- a/active/CVE-2010-2942
+++ b/active/CVE-2010-2942
@@ -7,8 +7,8 @@ References:
jmm> https://bugzilla.redhat.com/show_bug.cgi?id=624903
Notes:
Bugs:
-upstream: needed
+upstream: pending (2.6.36-rc3) [1c40be1]
2.6.32-upstream-stable: needed
linux-2.6: needed
-2.6.26-lenny-security: needed
+2.6.26-lenny-security: pending (2.6.26-25) [bugfix/all/net-sched-fix-some-kernel-memory-leaks.patch]
2.6.32-squeeze-security: needed
diff --git a/active/CVE-2010-2943 b/active/CVE-2010-2943
index 12cbb42f8..a592e0613 100644
--- a/active/CVE-2010-2943
+++ b/active/CVE-2010-2943
@@ -10,5 +10,5 @@ Bugs:
upstream: release (2.6.35) [7dce11db,7124fe0a,1920779e,7b6259e7]
2.6.32-upstream-stable: needed
linux-2.6: needed
-2.6.26-lenny-security: needed
+2.6.26-lenny-security: needed "issue goes back to when inode chunk delection was added - not sure if that was after .26. need to try test case in http://oss.sgi.com/archives/xfs/2010-06/msg00191.html"
2.6.32-squeeze-security: needed
diff --git a/active/CVE-2010-2946 b/active/CVE-2010-2946
index 814475fef..75006e6e0 100644
--- a/active/CVE-2010-2946
+++ b/active/CVE-2010-2946
@@ -7,5 +7,5 @@ Bugs:
upstream: released (2.6.36-rc1)
2.6.32-upstream-stable: released (2.6.32.19)
linux-2.6: pending (2.6.32-21)
-2.6.26-lenny-security: needed
+2.6.26-lenny-security: pending (2.6.26-25) [bugfix/all/jfs-dont-allow-os2-xattr-namespace-overlap-with-others.patch]
2.6.32-squeeze-security: pending (2.6.32-21)

© 2014-2024 Faster IT GmbH | imprint | privacy policy