Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 117040 - Kernel: Check for MAY_SATTR before setting NFS ACLs (CVE-2005-3623)
Summary: Kernel: Check for MAY_SATTR before setting NFS ACLs (CVE-2005-3623)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: [linux < 2.6.14.5]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-28 18:17 UTC by kfm
Modified: 2009-05-03 15:56 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description kfm 2005-12-28 18:17:37 UTC
Hi, I'm requesting that 2.6.14.5 is folded in to the genpatches trunk in order to form the basis of a gentoo-sources-2.6.14-r6 release and benefit other *-sources ebuilds. I've rolled a local set of genpatches and am providing an URL here (in the event that it might save you a few minutes of preparation):

Tarballs: http://recruit2recruit.net/kerframil/patches/
Split-out: http://recruit2recruit.net/kerframil/patches/genpatches-trunk/

Only changes in my trunk are as follows:

* Folds in 2.6.14.5 patches
* Bumps squashfs patch to 2.2-r2 (previous identification string was "Squashfs 2.2 (released 2005/07/03)", this one is "Squashfs 2.2-r2 (released 2005/09/08)")

Also worthy of note is that this addresses a security issue filed as CVE-2005-3623.
Comment 1 kfm 2005-12-28 18:19:46 UTC
Here's the link for the commit that addresses the aformentioned security buglet: http://kernel.org/git/?p=linux/kernel/git/gregkh/linux-2.6.14.y.git;a=commitdiff;h=0a63dca5ae2f975e08deae7e6c743a477af04367
Comment 2 Daniel Drake (RETIRED) gentoo-dev 2005-12-29 08:55:07 UTC
on its way out, thanks a lot!

I forgot the speakup patch by accident, but I just checked with interdiff and it is exactly the same, the only difference is that date string.
Comment 3 Tim Yamin (RETIRED) gentoo-dev 2006-01-10 11:01:27 UTC
Reopen for other sources.
Comment 4 Tim Yamin (RETIRED) gentoo-dev 2006-01-10 11:20:29 UTC
Reassigning.
Comment 5 Tim Yamin (RETIRED) gentoo-dev 2006-01-10 11:27:51 UTC
CCing maintainers: please either upgrade to 2.6.14.5 *or* fix with the patch in the URL. Thanks.

hardened-sources-2.6: hardened herd
mips-sources-2.6.13: Kumba
rsbac-sources-2.6: kang
usermode-sources-2.6: dsd
xbox-sources-2.6: gimli
Comment 6 kfm 2006-01-10 17:47:15 UTC
Re: hardened-sources, this was already fixed in hardened-sources-2.6.14-r3.
Comment 7 Daniel Drake (RETIRED) gentoo-dev 2006-01-21 15:39:22 UTC
usermode now on 2.6.15
Comment 8 Tim Yamin (RETIRED) gentoo-dev 2006-01-22 16:23:13 UTC
Toggle status.
Comment 9 Tim Yamin (RETIRED) gentoo-dev 2006-04-15 12:03:41 UTC
All fixed now, closing bug.