First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 139641
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 139641 depends on: Show dependency tree
Show dependency graph
Bug 139641 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-07-07 23:15 0000
9 From: Ian Abbott <abbotti@mev.co.uk>
  10 
  11 This patch limits the amount of outstanding 'write' data that can be
  12 queued up for the ftdi_sio driver, to prevent userspace DoS attacks (or
  13 simple accidents) that use up all the system memory by writing lots of
  14 data to the serial port.
  15 
  16 The original patch was by Guillaume Autran, who in turn based it on the
  17 same mechanism implemented in the 'visor' driver.  I (Ian Abbott)
  18 re-targeted the patch to the latest sources, fixed a couple of errors,
  19 renamed his new structure members, and updated the implementations of
  20 the 'write_room' and 'chars_in_buffer' methods to take account of the
  21 number of outstanding 'write' bytes.  It seems to work fine, though at
  22 low baud rates it is still possible to queue up an amount of data that
  23 takes an age to shift (a job for another day!).

------- Comment #1 From Harlan Lieberman-Berg (RETIRED) 2006-09-02 19:46:52 0000 -------
Also never ASSIGNED.

------- Comment #2 From Harlan Lieberman-Berg (RETIRED) 2006-09-02 20:01:06 0000 -------
Maintainers, please patch or preferrably bump to 2.6.17.7 (That's included in
genpatches 2.6.16-6)

rsbac-sources-2.6: kang
sh-sources-2.6: sh herd
usermode-sources-2.6: dang
xbox-sources-2.6: chrb, gimli
xen-sources-2.6: xen herd

------- Comment #3 From Harlan Lieberman-Berg (RETIRED) 2006-09-02 20:04:24 0000 -------
Sorry for the spam, it's genpatches 2.6.17-6

------- Comment #4 From Daniel Gryniewicz 2006-09-06 15:09:32 0000 -------
This patch doesn't apply to 2.16, and you can't actually drive a USB serial
dongle from UML anyway, so usermode-sources is okay without this one.

------- Comment #5 From Andrew Ross (RETIRED) 2006-09-10 04:38:36 0000 -------
xen-sources bumped to 2.6.16.28

------- Comment #6 From Harlan Lieberman-Berg (RETIRED) 2006-11-01 19:04:49 0000 -------
SH, RSBAC, still vulnerable in this one as well. Please patch or bump.

------- Comment #7 From Guillaume Destuynder (RETIRED) 2006-11-09 06:40:08 0000 -------
rsbac-sources bumped to 2.6.18 in ~

------- Comment #8 From Harlan Lieberman-Berg (RETIRED) 2006-11-09 18:27:45 0000 -------
SH Sources no longer covered by Gentoo Security. Closing bug.

First Last Prev Next    No search results available      Search page      Enter new bug