From 0394957db79db8afcae11908388c24464b8d744f Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Fri, 22 Feb 2008 21:53:05 +0000 Subject: retire some issues git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@1140 e094ebfe-e918-0410-adfb-c712417f3574 --- retired/CVE-2006-4814 | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 retired/CVE-2006-4814 (limited to 'retired/CVE-2006-4814') diff --git a/retired/CVE-2006-4814 b/retired/CVE-2006-4814 new file mode 100644 index 00000000..93d4ae2a --- /dev/null +++ b/retired/CVE-2006-4814 @@ -0,0 +1,21 @@ +Candidate: CVE-2006-4814 +References: + http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2f77d107050abc14bc393b34bdb7b91cf670c250 +Description: + The mincore function in the Linux kernel before 2.4.33.6 does not + properly lock access to user space, which has unspecified impact and + attack vectors, possibly related to a deadlock. +Ubuntu-Description: + Doug Chapman discovered an improper lock handling in the mincore() + function. A local attacker could exploit this to cause an eternal + hang in the kernel, rendering the machine unusable. +Notes: +Bugs: +upstream: released (2.6.20-rc2), released (2.4.34-rc3) +linux-2.6: released (2.6.18.dfsg.1-9) +2.6.18-etch-security: released (2.6.18.dfsg.1-9) +2.6.8-sarge-security: released (2.6.8-16sarge7) [mincore_hang.dpatch, mincore-fixes.dpatch] +2.4.27-sarge-security: released (2.4.27-10sarge6) [239_mincore-hang.diff] +2.6.12-breezy-security: released (2.6.12-10.43) +2.6.15-dapper-security: released (2.6.15-28.51) +2.6.17-edgy-security: released (2.6.17.1-11.35) -- cgit v1.2.3