From 6471f3dab8b9f08bf043c1fcc49f8a0bf467300a Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Mon, 30 Apr 2007 17:08:05 +0000 Subject: retire several issues git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@774 e094ebfe-e918-0410-adfb-c712417f3574 --- retired/CVE-2006-3741 | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 retired/CVE-2006-3741 (limited to 'retired/CVE-2006-3741') diff --git a/retired/CVE-2006-3741 b/retired/CVE-2006-3741 new file mode 100644 index 00000000..ef3e5c81 --- /dev/null +++ b/retired/CVE-2006-3741 @@ -0,0 +1,20 @@ +Candidate: CVE-2006-3741 +References: + http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b8444d00762703e1b6146fce12ce2684885f8bf6 +Description: + The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and + 2.6 before 2.6.18, when running on Itanium systems, does not properly + track the reference count for file descriptors, which allows local + users to cause a denial of service (file descriptor consumption). +Ubuntu-Description: +Notes: + dannf> I don't think 2.4 is affected - there are no existing calls to fput +Bugs: +upstream: released (2.6.18) +linux-2.6: released (2.6.18-1) +2.6.8-sarge-security: released (2.6.8-16sarge6) [perfmon-fd-refcnt.dpatch] +2.4.27-sarge-security: N/A +2.6.10-hoary-security: ignored +2.6.12-breezy-security: ignored +2.6.15-dapper-security: ignored +2.6.17-edgy: released (2.6.17-10.31) -- cgit v1.2.3