| Summary: | Linux <2.6.26.4 sctp: fix random memory dereference with SCTP_HMAC_IDENT option (CVE-2008-4113) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Robert Buchholz (RETIRED) <rbu> |
| Component: | Kernel | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | normal | CC: | kernel, kfm |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.26.y.git;a=commit;h=d97240552cd98c4b07322f30f66fd9c3ba4171de | ||
| Whiteboard: | [linux <2.6.25.17] [linux >=2.6.26 <2.6.26.4] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Robert Buchholz (RETIRED)
2008-09-17 19:38:18 UTC
Some further observations: * Also included as of 2.6.25.17 - updating the status whiteboard accordingly. * Fixed in genpatches-2.6.25-11 (gentoo-sources currently being the only consumer) * Fixed in >=hardened-sources-2.6.25-r6 and >=hardened-sources-2.6.26-r2 |