Summary: | kernel 5.14+ <{5.16.5,5.15.19},: use-after-free of user namespace on shm and mqueue destruction | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Michał Górny <mgorny> |
Component: | Kernel | Assignee: | Gentoo Kernel Security <security-kernel> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | flow |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://www.openwall.com/lists/oss-security/2022/01/29/1 | ||
Whiteboard: | |||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 832716 | ||
Bug Blocks: |
Description
Michał Górny
![]() ![]() ![]() ![]() Oh, and thanks to flow@ for reporting it on IRC. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8a1a81e544afce367e5430de02df365922f97128 commit 8a1a81e544afce367e5430de02df365922f97128 Author: Mike Pagano <mpagano@gentoo.org> AuthorDate: 2022-02-04 23:51:09 +0000 Commit: Mike Pagano <mpagano@gentoo.org> CommitDate: 2022-02-04 23:51:09 +0000 sys-kernel/gentoo-sources: Autostablize for security bug per policy Remove affected kernels Bug: https://bugs.gentoo.org/832717 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Mike Pagano <mpagano@gentoo.org> sys-kernel/gentoo-sources/Manifest | 18 -------------- .../gentoo-sources/gentoo-sources-5.15.16.ebuild | 28 ---------------------- .../gentoo-sources/gentoo-sources-5.15.17.ebuild | 28 ---------------------- .../gentoo-sources/gentoo-sources-5.15.18.ebuild | 28 ---------------------- .../gentoo-sources/gentoo-sources-5.15.19.ebuild | 2 +- .../gentoo-sources/gentoo-sources-5.16.2.ebuild | 28 ---------------------- .../gentoo-sources/gentoo-sources-5.16.3.ebuild | 28 ---------------------- .../gentoo-sources/gentoo-sources-5.16.4.ebuild | 28 ---------------------- 8 files changed, 1 insertion(+), 187 deletions(-) All done! |