Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 634874 - <sys-kernel/gentoo-sources-4.13.8: alsa: use-after-free in /dev/snd/seq (CVE-2017-15265)
Summary: <sys-kernel/gentoo-sources-4.13.8: alsa: use-after-free in /dev/snd/seq (CVE-...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
URL: https://cve.mitre.org/cgi-bin/cvename...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-20 15:24 UTC by Stefan Gast
Modified: 2022-03-26 00:27 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gast 2017-10-20 15:24:34 UTC
Kernels before 4.13.8 are affected by CVE-2017-15265:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15265
http://seclists.org/oss-sec/2017/q4/58

4.13.8 has a patch for it, which also compiles with stable (amd64) sys-kernel/gentoo-sources-4.12.12:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?h=v4.13.8&id=71c766e18dd3f321bd450ec7c0c20643b2c4b74e

(This is my first security related bug report here, so please tell me if I'm doing something wrong. Apologies for any mistakes in advance.)
Comment 1 Stefan Gast 2019-01-07 13:28:40 UTC
I guess this was overshadowed by the Spectre / Meltdown disaster last year. So let's check the currently oldest kernel versions in the tree for the patch:

sys-kernel/gentoo-sources-4.4.164: patched (commit 23709ae9b61429502fcd4686e7a97333f3b3544a)

sys-kernel/gentoo-sources-4.9.140: patched (commit 35b84860667ff081eee56b62f3db2a28ca8a3823)

sys-kernel/gentoo-sources-4.14.83: patched (commit 71105998845fb012937332fe2e806d443c09e026)

sys-kernel/gentoo-sources-4.19.8: patched (commit 71105998845fb012937332fe2e806d443c09e026)

sys-kernel/gentoo-sources-4.20.0: patched (commit 71105998845fb012937332fe2e806d443c09e026)

As there is no unpatched version of sys-kernel/gentoo-sources left in the tree, IMHO this is resolved for sys-kernel/gentoo-sources. I haven't checked the other sys-kernel/*-sources ebuilds.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-26 00:27:29 UTC
Fixed in 4.9.57, 4.14