Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 86976 - Kernel: Local DOS through reiserfs (GENERIC-MAP-NOMATCH)
Summary: Kernel: Local DOS through reiserfs (GENERIC-MAP-NOMATCH)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/bid/1153...
Whiteboard: [linux <2.6.9]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-03-28 07:23 UTC by Omkhar Arasaratnam (RETIRED)
Modified: 2009-07-12 19:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Omkhar Arasaratnam (RETIRED) gentoo-dev 2005-03-28 07:23:17 UTC
Multiple Kernel vulnerabilities were released to BugTraq:

http://www.securityfocus.com/bid/12261?ref=rss
http://www.securityfocus.com/bid/11491?ref=rss
http://www.securityfocus.com/bid/11492?ref=rss
http://www.securityfocus.com/bid/11533?ref=rss
http://www.securityfocus.com/bid/12195?ref=rss

Can these please be applied to all relevant kernels? SUSE and Ubuntu already have fixed kernels released.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-03-28 09:04:58 UTC
http://www.securityfocus.com/bid/12261?ref=rss
is CAN-2005-0003, Gentoo bug 72452, resolved

http://www.securityfocus.com/bid/11491?ref=rss
http://www.securityfocus.com/bid/11492?ref=rss
are CAN-2004-0814, Gentoo bug 68421, resolved

http://www.securityfocus.com/bid/12195?ref=rss
is CAN-2005-0504, Gentoo bug 77094, under correction

http://www.securityfocus.com/bid/11533?ref=rss
is a NO-CAN reiserfs localdos, fixed in 2.6.9

So we'll restrict this to only the reiserfs local dos for which I can't find a duplicate:

==============================================================
The Linux kernel is affected by a local denial of service vulnerability in its ReiserFS file system functionality. This issue is due to a failure of the application to properly handle files under certain conditions.

An attacker may leverage this issue to trigger a livelock in the affected file system, forcing a user to restart the computer to return it to proper functionality.
==============================================================
Fixed in vanilla 2.6.9
Comment 2 Omkhar Arasaratnam (RETIRED) gentoo-dev 2005-04-12 18:47:29 UTC
So... in light of this can we mask xfs utils on ppc64 for anything lower than 2.6.11-r6?
Comment 3 Omkhar Arasaratnam (RETIRED) gentoo-dev 2005-04-12 18:49:19 UTC
woopse wrong bug ;-)
Comment 4 Tim Yamin (RETIRED) gentoo-dev 2005-04-15 13:31:07 UTC
Closing bug as fixed; all the issues reported here have already been dealt with in other bugs; and SecurityFocus has no cross-references or details about the reiserfs issue so we can't do anything about that, and all kernels should be >= 2.6.9 by now anyway...