Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 158781 - Linux 2.6.x squashfs double free (CVE-2006-5701)
Summary: Linux 2.6.x squashfs double free (CVE-2006-5701)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://projects.info-pull.com/mokb/MO...
Whiteboard: [gp <2.6.18-8] [gp >=2.6.19-1 <2.6.1...
Keywords:
Depends on:
Blocks:
 
Reported: 2006-12-21 18:37 UTC by Daniel Drake (RETIRED)
Modified: 2009-11-20 09:23 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
patch (patch,11.93 KB, patch)
2006-12-23 08:07 UTC, Daniel Drake (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Drake (RETIRED) gentoo-dev 2006-12-21 18:37:49 UTC
The squashfs module of the Linux kernel (2.6.x) fails to properly handle corrupted fs structures, leading to a denial of service and possible data corruption condition. A specially crafted squashfs image will cause the kernel to double free a buffer when a read operation is performed on the corrupted filesystem.

This affects all kernels that include genpatches-extras
Comment 1 Daniel Drake (RETIRED) gentoo-dev 2006-12-23 08:07:29 UTC
Created attachment 104637 [details, diff]
patch

Committed upstream but not yet released
Comment 2 Daniel Drake (RETIRED) gentoo-dev 2007-01-05 06:31:17 UTC
Fixed versions:
gentoo-sources-2.6.18-r6
genpatches-2.6.18-8
gentoo-sources-2.6.19-r3
genpatches-2.6.19-4
Comment 3 Harlan Lieberman-Berg (RETIRED) gentoo-dev 2007-05-21 23:40:16 UTC
Way out of version range. Closing.
Comment 4 Bjoern Tropf (RETIRED) gentoo-dev 2009-11-20 09:22:15 UTC
Reopen bug to apply a valid whiteboard.