http://www.suse.de/de/security/2004_37_kernel.html contains the details. CVE is CAN-2004-0816 Although this only affects kernels <2.6.8, we still have ebuilds around where the latest ones are 2.6.7 (e.g. hardened-dev-sources).
Created attachment 42326 [details, diff] Patch
Ok, all done. The following externally maintained sources remain, adding maintainers to the CC. hardened-dev-sources - Adding hardened@gentoo.org. mips-sources - Adding kumba@gentoo.org. rsbac-dev-sources - Adding kang@gentoo.org.
CAN-2004-0816 => Done for rsbac-dev-sources.
this should be added to a revbump of g-d-s-2.6.7 as well for sparc as it can't use >=2.6.8
It applies, compiles, and boots without error on hardened-dev-sources-2.6.5-r5. Personally, I feel that it would at least rate a ~arch ebuild, especially since y'all apparently felt that this was sufficient to pull all hardened-dev-sources ebuilds, rather than merely hard-masking them.
hardened-dev-sources seems to be patched. Thanks for patching Joshua but please remember to comment on the bug.
Moving to newly-created kernel-specific category
I think it's ready for a GLSA, as mips-sources is not required to issue the GLSA. kumba: please apply patch to mips-sources to benefit from GLSA
This is getting augmented with bug #62524 and bug #68421 for a GLSA...
*** Bug 71586 has been marked as a duplicate of this bug. ***
I am seeing indications of this problem in gentoo-dev-sources-2.6.9-r1 and -r4 George
mips-sources updated.
All kernels fixed, closing bug; notifications are being migrated away from GLSAs for kernels, more news coming soon so stay tuned :-]
for ipv4: http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=1fe7d5a3b74732a0f168c18aa64249bcc280fbb8 for the ipv6 part: http://git.kernel.org/?p=linux/kernel/git/tglx/history.git;a=commit;h=8bd22e22e883efb5f56d9045f631f792784a5e4c