First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 158781
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Daniel Drake <dsd@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
patch patch patch Daniel Drake 2006-12-23 08:07 0000 11.93 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 158781 depends on: Show dependency tree
Bug 158781 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-12-21 18:37 0000
The squashfs module of the Linux kernel (2.6.x) fails to properly handle
corrupted fs structures, leading to a denial of service and possible data
corruption condition. A specially crafted squashfs image will cause the kernel
to double free a buffer when a read operation is performed on the corrupted
filesystem.

This affects all kernels that include genpatches-extras

------- Comment #1 From Daniel Drake 2006-12-23 08:07:29 0000 -------
Created an attachment (id=104637) [details]
patch

Committed upstream but not yet released

------- Comment #2 From Daniel Drake 2007-01-05 06:31:17 0000 -------
Fixed versions:
gentoo-sources-2.6.18-r6
genpatches-2.6.18-8
gentoo-sources-2.6.19-r3
genpatches-2.6.19-4

------- Comment #3 From Harlan Lieberman-Berg (RETIRED) 2007-05-21 23:40:16 0000 -------
Way out of version range. Closing.

------- Comment #4 From Bjoern Tropf 2009-11-20 09:22:15 0000 -------
Reopen bug to apply a valid whiteboard.

First Last Prev Next    No search results available      Search page      Enter new bug