Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 37293
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 37292
Assigned To: x86-kernel@gentoo.org (DEPRECATED) <x86-kernel@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Christian Gut <cycloon@is-root.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
patch-do_mremap Patch that fix the vulnerability patch Marc Bevand 2004-01-05 06:20 0000 660 bytes Details | Diff
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 37293 depends on: Show dependency tree
Bug 37293 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-01-05 05:58 0000
more details: http://isec.pl/vulnerabilities/isec-0012-mremap.txt

seems to affect 2.2, 2.4, and 2.6 series

Reproducible: Always
Steps to Reproduce:

------- Comment #1 From Christian Gut 2004-01-05 06:00:00 0000 -------
forgot this in the details field:
http://kernel.org/pub/linux/kernel/v2.4/testing/patch-2.4.24.log

------- Comment #2 From Christian Gut 2004-01-05 06:18:55 0000 -------
- 2.4.24-rc1 was released as 2.4.24 with no changes.
http://marc.theaimsgroup.com/?l=linux-kernel&m=107331127632230&w=2

seems to be critical

------- Comment #3 From Marc Bevand 2004-01-05 06:20:04 0000 -------
Created an attachment (id=23184) [details]
Patch that fix the vulnerability

I have extracted this patch from the 2.4.23 -> 2.4.24-rc1 changes.

Marcelo Tosatti has released 2.4.24 because of this vulnerability.
So it may be a better idea to upgrade to 2.4.24 instead of backporting
the patch.

------- Comment #4 From Boris 2004-01-05 06:45:50 0000 -------
Here is the official diff from kernel.org
http://www.kernel.org/diff/diffview.cgi?file=%2Fpub%2Flinux%2Fkernel%2Fv2.4%2Fpatch-2.4.24.bz2;z=16
Matches your patch (did you take it from kernel.org?), so this link is just for completion.

------- Comment #5 From SpanKY 2004-01-05 10:04:18 0000 -------

*** This bug has been marked as a duplicate of 37292 ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug