Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 143538 - Kernel: UDF filesystem has some bugs on truncating (CVE-2006-4145)
Summary: Kernel: UDF filesystem has some bugs on truncating (CVE-2006-4145)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://git.kernel.org/?p=linux/kernel...
Whiteboard: [linux <2.6.16.28] [linux >=2.6.17 <2...
Keywords:
Depends on:
Blocks:
 
Reported: 2006-08-11 01:34 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2009-07-11 14:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-08-11 01:34:54 UTC
Found by Alan Cox from Red Hat.

Not sure wether this is public.

> > Hi all,
> > I found that UDF has bugs on truncating.
> > When you do this:
> >     dd if=/dev/zero of=aaa bs=1024k count=2 seek=3000
> > , Linux will hang and die.
> > The platform is Linux 2.6.16 on MIPS malta board.
> 
> Ok I eventually sort of reproduced this on x86-64. It took a while
> because in my environment I see a crash 2 or 3 hours after the test is
> run, and that crash is on hardware that doesn't otherwise crash and
> seems to be repeatable.
Comment 1 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2006-08-23 07:24:09 UTC
public now  CVE-2006-4145, thanks gustavoz
Comment 2 Harlan Lieberman-Berg (RETIRED) gentoo-dev 2006-09-02 20:42:57 UTC
Maintainers, please bump.

rsbac-sources-2.6: kang
sh-sources-2.6: sh herd
suspend2-sources-2.6: phreak
usermode-sources-2.6: dang
xbox-sources-2.6: gimli, chrb
xen-sources-2.6: xen herd
Comment 3 Christian Heim (RETIRED) gentoo-dev 2006-09-03 05:17:36 UTC
suspend2-sources bumped as of 13:16 UTC.
Comment 4 Daniel Gryniewicz (RETIRED) gentoo-dev 2006-09-06 16:48:52 UTC
usermode-sources-2.6.16-r5 added.
Comment 5 Andrew Ross (RETIRED) gentoo-dev 2006-09-10 04:39:47 UTC
xen-sources bumped to 2.6.16.28
Comment 6 Harlan Lieberman-Berg (RETIRED) gentoo-dev 2006-11-01 19:07:37 UTC
RSBAC, Xbox, SH, please bump or patch.
Comment 7 Guillaume Destuynder (RETIRED) gentoo-dev 2006-11-09 06:43:08 UTC
rsbac-sources bumped to 2.6.18 in ~
Comment 8 Harlan Lieberman-Berg (RETIRED) gentoo-dev 2006-12-05 19:05:56 UTC
Xbox and SH are not covered by Security. Closing.