gentoo-sources-3.7.10 has the fix inside. Could you please update aufs-sources to 3.7.10, too? Reproducible: Always
All aufs-sources versions that are currently in the Portage tree are affected. You might want to revision bump 3.6.11 as well with the backported fix.
Thanks for pointing at this.
+*aufs-sources-3.7.10 (03 Mar 2013) +*aufs-sources-3.6.11-r1 (03 Mar 2013) + + 03 Mar 2013; Justin Lecher <jlec@gentoo.org> -aufs-sources-3.6.11.ebuild, + +aufs-sources-3.6.11-r1.ebuild, -aufs-sources-3.7.2.ebuild, + -aufs-sources-3.7.3.ebuild, -aufs-sources-3.7.4.ebuild, + -aufs-sources-3.7.6.ebuild, -aufs-sources-3.7.7.ebuild, + -aufs-sources-3.7.8.ebuild, +aufs-sources-3.7.10.ebuild: + Version Bump and remove old to fix CVE-2013-1763, #460126 +