First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 77923
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Brandon Hale (RETIRED) <tseng@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
nfs-client-odirect.patch O_DIRECT fix from -bk patch Brandon Hale (RETIRED) 2005-01-13 18:51 0000 1.46 KB Details | Diff
linux-2.6.10-77923.patch Patch patch Tim Yamin (RETIRED) 2005-01-15 14:08 0000 1.07 KB Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 77923 depends on: Show dependency tree
Bug 77923 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-01-13 18:50 0000
I caught this fix in the changelog linked above, already in Linus's tree.
From the log:

   * [SECURITY] NFS client O_DIRECT error case fix:
     - Add patch stolen-from-head_nfs-client-odirect.dpatch.
 .
   The NFS direct-io error return path for request sizes greater than
   MAX_DIRECTIO_SIZE fails to initialize the returned page struct array
   pointer to NULL.
 .
   Discovered using AKPM's ext3-tools: odwrite -ko 0 16385 foo

Exploitability of this flaw seems to be undisclosed at this time.
I've broken out the patch, attaching below.

------- Comment #1 From Brandon Hale (RETIRED) 2005-01-13 18:51:21 0000 -------
Created an attachment (id=48436) [edit]
O_DIRECT fix from -bk

Broken out from Ubuntu kernel sources, pulled from linus-bk

------- Comment #2 From Brandon Hale (RETIRED) 2005-01-13 18:53:06 0000 -------
This is fixed without a changelog entry in -ac. hardened-dev-sources 2.6.10
includes -ac8, and is unaffected. Will go stable soon.

------- Comment #3 From Brandon Hale (RETIRED) 2005-01-14 07:18:55 0000 -------
hardened-dev-sources stable, resolved for us.

------- Comment #4 From Tim Yamin (RETIRED) 2005-01-15 14:08:35 0000 -------
Created an attachment (id=48583) [edit]
Patch

------- Comment #5 From Joshua Kinard 2005-01-18 19:00:50 0000 -------
mips-sources patched

------- Comment #6 From Daniel Drake 2005-01-19 03:45:03 0000 -------
gentoo-dev-sources is done

------- Comment #7 From Thierry Carrez (RETIRED) 2005-03-16 03:16:35 0000 -------
Mass-Ccing kern-sec@gentoo.org to make sure Kernel Security guys know about all
of these...

------- Comment #8 From Tim Yamin (RETIRED) 2005-03-29 05:51:12 0000 -------
Following sources still need this fix:

hppa-sources:- Adding GMSoft...
pegasos-sources:- Adding dholm...
rsbac-sources:- Adding kang...

------- Comment #9 From Tim Yamin (RETIRED) 2005-03-29 05:51:26 0000 -------
Following sources still need this fix:

hppa-sources:- Adding GMSoft...
pegasos-sources:- Adding dholm...
rsbac-sources:- Adding kang...

------- Comment #10 From Guillaume Destuynder (RETIRED) 2005-04-08 01:02:44 0000 -------
just a note: this vuln is not present in rsbac kernels.

------- Comment #11 From David Holm (RETIRED) 2005-04-14 03:33:58 0000 -------
pegasos-sources fixed

------- Comment #12 From Tim Yamin (RETIRED) 2005-07-24 09:26:43 0000 -------
All fixed, closing bug.

------- Comment #13 From Robert Buchholz 2009-05-03 14:44:58 0000 -------
http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=6bf784fa4fbe697cc87b42f65bce319bf9a98c20

First Last Prev Next    No search results available      Search page      Enter new bug