First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 138617
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Gustavo Zacarias (RETIRED) <gustavoz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
CVE-2006-0039.patch CVE-2006-0039 split patch for 2.4.32 patch Gustavo Zacarias (RETIRED) 2006-06-30 12:02 0000 1.45 KB Details | Diff
CVE-2006-1857.patch CVE-2006-1857 split patch for 2.4.32 patch Gustavo Zacarias (RETIRED) 2006-06-30 12:02 0000 631 bytes Details | Diff
CVE-2006-1858.patch CVE-2006-1858 split patch for 2.4.32 patch Gustavo Zacarias (RETIRED) 2006-06-30 12:03 0000 1.36 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 138617 depends on: Show dependency tree
Show dependency graph
Bug 138617 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-06-30 12:01 0000
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0039
Race condition in the do_add_counters function in netfilter for Linux kernel
2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory
by triggering the race condition in a way that produces a size value that is
inconsistent with allocated memory, which leads to a buffer over-read in
IPT_ENTRY_ITERATE.

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1857
Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote
attackers to cause a denial of service (crash) and possibly execute arbitrary
code via a malformed HB-ACK chunk.

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1858
SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial
of service (crash) and possibly execute arbitrary code via a chunk length that
is inconsistent with the actual length of provided parameters.

This are fixed in 2.4.33-rc2.

------- Comment #1 From Gustavo Zacarias (RETIRED) 2006-06-30 12:02:24 0000 -------
Created an attachment (id=90545) [edit]
CVE-2006-0039 split patch for 2.4.32

------- Comment #2 From Gustavo Zacarias (RETIRED) 2006-06-30 12:02:45 0000 -------
Created an attachment (id=90546) [edit]
CVE-2006-1857 split patch for 2.4.32

------- Comment #3 From Gustavo Zacarias (RETIRED) 2006-06-30 12:03:08 0000 -------
Created an attachment (id=90547) [edit]
CVE-2006-1858 split patch for 2.4.32

------- Comment #4 From Gustavo Zacarias (RETIRED) 2006-06-30 12:04:20 0000 -------
Patches split from the incremental 2.4.33-rc1 -> 2.4.33-rc2 patch from
kernel.org
sparc-sources-2.4.32-r6 will go in soon with the fixes, probably gentoo-sources
& hardened-sources need to fix as well.

------- Comment #5 From solar 2006-06-30 16:42:59 0000 -------
hardened-sources-2.4.32-r6 in portage with these 3 new patches plus one
additional 
patch for sysctl controlable grsecurity resource logging I whiped up last
night.
Marked older h-s-r4 stable.

Thank you Gustavo for pointing these patches out.

------- Comment #6 From Tim Yamin (RETIRED) 2006-07-02 08:21:11 0000 -------
gentoo-sources-2.4.32-r6 now in the tree with the patches, thanks Gustavo.

Maintainers: Please bump your sources to 2.4.33-rc2 or include security patches
from the genpatches patchset.

CCing:
openmosix-sources: cluster, voxus
rsbac-sources: kang
xbox-sources: chrb, gimli

------- Comment #7 From Gustavo Zacarias (RETIRED) 2006-07-03 18:25:50 0000 -------
sparc-sources-2.4.32-r6 stable.

------- Comment #8 From Tim Yamin (RETIRED) 2006-08-07 14:12:39 0000 -------
openmosix-sources, rsbac-sources, xbox-sources-2.4: Security masked.

------- Comment #9 From Harlan Lieberman-Berg (RETIRED) 2006-10-26 10:42:08 0000 -------
Openmosix, RSBAC, Xbox 2.4 you are still vulnerable.

------- Comment #10 From Harlan Lieberman-Berg (RETIRED) 2006-11-01 18:58:46 0000 -------
RSBAC and OpenMOSIX are still vulnerable, as far as I can tell.  Kang, Tantive,
please fix.  Xbox-2.4 is hardmasked for security packages. I'll wait three days
and then assign those to treecleaners, unless there are objections.

------- Comment #11 From Daniel Drake 2006-11-01 19:34:27 0000 -------
Assign what to treecleaners?

------- Comment #12 From Daniel Drake 2006-11-01 19:37:27 0000 -------
Also, not entirely sure why you added kernel@, none of the mentioned kernels
are maintained by the kernel herd

------- Comment #13 From Harlan Lieberman-Berg (RETIRED) 2006-11-02 08:22:25 0000 -------
Whoops, the kernel@ CC was an accident. I meant to add it to another bug.
Assign xbox-sources-2.4.32-r1 to Treecleaners.

------- Comment #14 From Guillaume Destuynder (RETIRED) 2006-11-20 06:02:32 0000 -------
(In reply to comment #10)
> RSBAC and OpenMOSIX are still vulnerable, as far as I can tell.  Kang, Tantive,
> please fix.  Xbox-2.4 is hardmasked for security packages. I'll wait three days
> and then assign those to treecleaners, unless there are objections.
> 

not sure how old that is but since its re-opened with no reply:
there is no 2.4 rsbac kernel, patches for rsbac are in sys-kernel/hardened (the
2.4 one only)

------- Comment #15 From Harlan Lieberman-Berg (RETIRED) 2006-12-21 14:01:37 0000 -------
Looks fixed to me. Closing.

First Last Prev Next    No search results available      Search page      Enter new bug