<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>57826</bug_id>
          
          <creation_ts>2004-07-21 01:41 0000</creation_ts>
          <short_desc>sys-kernel/*: Linux Kernel Equalizer Load Balancer Device Driver Local Denial Of Service Vulnerability</short_desc>
          <delta_ts>2004-09-13 08:29:52 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0596</bug_file_loc>
          <status_whiteboard>B3 [glsa?] plasmaroo</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>gregkh@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-07-21 01:41:39 0000</bug_when>
            <thetext>Just noticed this in the SecurityFocus newsletter:

The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users to cause a denial of service via a non-existent device name that triggers a null dereference.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2004-07-21 04:30:21 0000</bug_when>
            <thetext>All done; now I&apos;m adding on the externally maintained 2.6 sources which need patching for this issue:

gentoo-dev-sources - Adding gregkh...
hardened-dev-sources - Adding Gentoo/Hardened team...
hppa-dev-sources - Adding GMSoft...
mips-sources - Adding `Kumba...
rsbac-dev-sources - Adding kang...
pegasos-dev-sources - Adding dholm...

If you need a patch for this issue look in ${PORTDIR}/sys-kernel/{aa,ck,...}-sources/files.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kang@gentoo.org</who>
            <bug_when>2004-07-22 03:56:35 0000</bug_when>
            <thetext>CAN-0596 patched for rsbac-dev-sources-2.6.7-r3</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kumba@gentoo.org</who>
            <bug_when>2004-07-22 19:19:43 0000</bug_when>
            <thetext>mips-sources fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tseng@gentoo.org</who>
            <bug_when>2004-07-24 06:15:45 0000</bug_when>
            <thetext>hardened-dev-sources fixed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dholm@gentoo.org</who>
            <bug_when>2004-07-24 07:24:14 0000</bug_when>
            <thetext>pegasos-dev-sources fixed</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gregkh@gentoo.org</who>
            <bug_when>2004-08-06 17:12:41 0000</bug_when>
            <thetext>gentoo-dev-sources fixed in 2.6.7-r12</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gmsoft@gentoo.org</who>
            <bug_when>2004-08-09 16:33:00 0000</bug_when>
            <thetext>Fixed on hppa.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-09-02 06:34:15 0000</bug_when>
            <thetext>Everyone is set, AFAICT...

This one was not included in the kernel GLSA 200408-24, but it is apparently covered by it.

plasmaroo: please comment on the GLSA need.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2004-09-13 08:29:52 0000</bug_when>
            <thetext>This should have been covered by GLSA 200408-24 as Koon has mentioned, so I&apos;m closing this as FIXED.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>