From 6471f3dab8b9f08bf043c1fcc49f8a0bf467300a Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Mon, 30 Apr 2007 17:08:05 +0000 Subject: retire several issues git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@774 e094ebfe-e918-0410-adfb-c712417f3574 --- retired/CVE-2006-5174 | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 retired/CVE-2006-5174 (limited to 'retired/CVE-2006-5174') diff --git a/retired/CVE-2006-5174 b/retired/CVE-2006-5174 new file mode 100644 index 000000000..104818194 --- /dev/null +++ b/retired/CVE-2006-5174 @@ -0,0 +1,22 @@ +Candidate: CVE-2006-5174 +References: + http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=52149ba6b0ddf3e9d965257cc0513193650b3ea8 +Description: + The copy_from_user function in the uaccess code in Linux kernel 2.6 + before 2.6.19-rc1, when running on s390, does not properly clear a + kernel buffer, which allows local user space programs to read + portions of kernel memory by "appending to a file from a bad + address," which triggers a fault that prevents the unused memory from + being cleared in the kernel buffer. +Ubuntu-Description: +Notes: + jmm> Fix from 2.6.18-3 was reverted, caused problems +Bugs: +upstream: released (2.6.18.1) +linux-2.6: needed +2.6.8-sarge-security: released (2.6.8-16sarge6) [s390-uaccess-memleak.dpatch] +2.4.27-sarge-security: released (2.4.27-10sarge5) [236_s390-uaccess-memleak.diff] +2.6.10-hoary-security: ignored +2.6.12-breezy-security: ignored +2.6.15-dapper-security: ignored +2.6.17-edgy: ignored -- cgit v1.2.3