Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 467964 (CVE-2013-2017)

Summary: Kernel : veth: double-free flaw in case of congestion (CVE-2013-2017)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: KernelAssignee: Gentoo Kernel Security <security-kernel>
Status: RESOLVED FIXED    
Severity: normal CC: kernel
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=957705
Whiteboard:
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2013-04-30 08:46:28 UTC
From ${URL} :

A flaw was found in the way Virtual Ethernet driver implementation in the Linux kernel handled skbs 
in case of congestion.

A remote attacker could potentially use this flaw to crash the system.

Introduced in:
2.6.33-rc1

Fixed in:
2.6.34

Upstream fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6ec82562ffc6f297d0de36d65776cff8e5704867

References:
http://marc.info/?l=linux-netdev&m=127310770900442&w=3
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-08-10 17:55:11 UTC
=sys-kernel/pf-sources-2.6.33_p4

only place this could still exist I think
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-10-25 00:34:45 UTC
No affected kernels in tree