summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2018-7754
diff options
context:
space:
mode:
authorBen Hutchings <ben@decadent.org.uk>2018-09-14 04:38:12 +0100
committerBen Hutchings <ben@decadent.org.uk>2018-09-14 04:38:26 +0100
commitb296a1a1a1f813b1e1758348845df26724575fad (patch)
treebe8a07073b030ac161f52c0e0e00462348c63c4e /retired/CVE-2018-7754
parentf122de2fd898220a0f690dccc26a7f11e505b569 (diff)
Retire CVE-2018-7754
Diffstat (limited to 'retired/CVE-2018-7754')
-rw-r--r--retired/CVE-2018-775416
1 files changed, 16 insertions, 0 deletions
diff --git a/retired/CVE-2018-7754 b/retired/CVE-2018-7754
new file mode 100644
index 00000000..a6d4a4ca
--- /dev/null
+++ b/retired/CVE-2018-7754
@@ -0,0 +1,16 @@
+Description: information leak vulnerablility
+References:
+ https://github.com/johnsonwangqize/cve-linux/blob/master/CVE-2018-7754.md
+ https://elixir.bootlin.com/linux/v4.16-rc4/source/drivers/block/aoe/aoeblk.c#L421
+Notes:
+ carnil> Likely as other reports from "ADLab of VenusTech" not reported to
+ carnil> upstream?
+ bwh> The upstream fix was to obscure logged pointer values by
+ bwh> default.
+Bugs:
+upstream: released (4.15-rc2) [ad67b74d2469d9b82aaa572d76474c95bc484d57]
+4.9-upstream-stable: ignored "debugfs restricted to root by default"
+3.16-upstream-stable: ignored "debugfs restricted to root by default"
+sid: released (4.15.4-1)
+4.9-stretch-security: ignored "debugfs restricted to root by default"
+3.16-jessie-security: ignored "debugfs restricted to root by default"

© 2014-2024 Faster IT GmbH | imprint | privacy policy