Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 57826 - sys-kernel/*: Linux Kernel Equalizer Load Balancer Device Driver Local Denial Of Service Vulnerability
Summary: sys-kernel/*: Linux Kernel Equalizer Load Balancer Device Driver Local Denial...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B3 [glsa?] plasmaroo
Keywords:
Depends on:
Blocks:
 
Reported: 2004-07-21 01:41 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2011-10-30 22:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2004-07-21 01:41:39 UTC
Just noticed this in the SecurityFocus newsletter:

The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users to cause a denial of service via a non-existent device name that triggers a null dereference.
Comment 1 Tim Yamin (RETIRED) gentoo-dev 2004-07-21 04:30:21 UTC
All done; now I'm adding on the externally maintained 2.6 sources which need patching for this issue:

gentoo-dev-sources - Adding gregkh...
hardened-dev-sources - Adding Gentoo/Hardened team...
hppa-dev-sources - Adding GMSoft...
mips-sources - Adding `Kumba...
rsbac-dev-sources - Adding kang...
pegasos-dev-sources - Adding dholm...

If you need a patch for this issue look in ${PORTDIR}/sys-kernel/{aa,ck,...}-sources/files.
Comment 2 Guillaume Destuynder (RETIRED) gentoo-dev 2004-07-22 03:56:35 UTC
CAN-0596 patched for rsbac-dev-sources-2.6.7-r3
Comment 3 Joshua Kinard gentoo-dev 2004-07-22 19:19:43 UTC
mips-sources fixed
Comment 4 Brandon Hale (RETIRED) gentoo-dev 2004-07-24 06:15:45 UTC
hardened-dev-sources fixed.
Comment 5 David Holm (RETIRED) gentoo-dev 2004-07-24 07:24:14 UTC
pegasos-dev-sources fixed
Comment 6 Greg Kroah-Hartman (RETIRED) gentoo-dev 2004-08-06 17:12:41 UTC
gentoo-dev-sources fixed in 2.6.7-r12
Comment 7 Guy Martin (RETIRED) gentoo-dev 2004-08-09 16:33:00 UTC
Fixed on hppa.
Comment 8 Thierry Carrez (RETIRED) gentoo-dev 2004-09-02 06:34:15 UTC
Everyone is set, AFAICT...

This one was not included in the kernel GLSA 200408-24, but it is apparently covered by it.

plasmaroo: please comment on the GLSA need.
Comment 9 Tim Yamin (RETIRED) gentoo-dev 2004-09-13 08:29:52 UTC
This should have been covered by GLSA 200408-24 as Koon has mentioned, so I'm closing this as FIXED.