Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 137626 - xt_sctp: fix endless loop caused by 0 chunk length (CVE-2006-3085)
Summary: xt_sctp: fix endless loop caused by 0 chunk length (CVE-2006-3085)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.kernel.org/pub/linux/kerne...
Whiteboard: [linux <2.6.16.21] [linux >=2.6.17 <2...
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-22 11:05 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2009-07-10 23:15 UTC (History)
8 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-06-22 11:05:17 UTC
Fix endless loop in the SCTP match similar to those already fixed in the
    SCTP conntrack helper (was CVE-2006-1527).
    
    Signed-off-by: Patrick McHardy <kaber@trash.net>
    Signed-off-by: Chris Wright <chrisw@sous-sol.org>
Comment 1 Tim Yamin (RETIRED) gentoo-dev 2006-06-24 13:04:49 UTC
dsd: Please bump genpatches-2.6.16 to .21.
Comment 2 Sebastian 2006-06-26 13:40:44 UTC
Hi!

2.6.16.22 is already out in the open, allthough I stumbled over it by accident. Is there an easy way to keep track of these updates? They're only on the kernel.org frontpage for the latest series (now 2.6.17).

Cheers
Sebastian
Comment 3 Daniel Drake (RETIRED) gentoo-dev 2006-07-01 04:51:58 UTC
Fixed in gentoo-sources-2.6.16-r11 / genpatches-2.6.16-23
Comment 4 Tim Yamin (RETIRED) gentoo-dev 2006-07-02 08:44:07 UTC
Maintainers please bump to 2.6.16.23/2.7.17.3 preferably or genpatches-2.6.16-13/genpatches-2.6.17-2:

ck-sources-2.6.16: marineam
ck-sources-2.6.17: marineam
hardened-sources-2.6: johnm, hardened
mips-sources-2.6.16: `Kumba
rsbac-sources-2.6: kang
sh-sources-2.6: vapier
suspend2-sources-2.6: brix
usermode-sources-2.6: dang
xbox-sources-2.6: chrb, gimli
xen-sources-2.6: chrb, agriffis
Comment 5 Daniel Gryniewicz (RETIRED) gentoo-dev 2006-07-03 11:04:49 UTC
usermode-sources done for 2.6.16.  There isn't a 2.6.17 yet, so it will get the newest genpatches when it's added.
Comment 6 Henrik Brix Andersen 2006-07-04 11:05:12 UTC
Fixed in sys-kernel/suspend2-sources-2.6.16-r10. 

sys-kernel/suspend2-sources-2.6.17* is not yet in portage.
Comment 7 Micheal Marineau (RETIRED) gentoo-dev 2006-07-09 16:39:28 UTC
Fixed in ck-sources-2.6.16_p12-r1 and ck-sources-2.6.17_p1-r1.
Comment 8 Tim Yamin (RETIRED) gentoo-dev 2006-08-07 14:01:40 UTC
All fixed, closing.