Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 158787 - Linux 2.6.x gfs2 init_journal denial of service (CVE-2006-6057)
Summary: Linux 2.6.x gfs2 init_journal denial of service (CVE-2006-6057)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://projects.info-pull.com/mokb/MO...
Whiteboard: [linux < 2.6.21][gp < 2.6.21-1][gento...
Keywords:
: 155355 (view as bug list)
Depends on:
Blocks:
 
Reported: 2006-12-21 18:55 UTC by Daniel Drake (RETIRED)
Modified: 2013-09-03 03:13 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Drake (RETIRED) gentoo-dev 2006-12-21 18:55:13 UTC
Linux 2.6.x gfs2 filesystem code fails to properly handle corrupted data structures, leading to an exploitable denial of service issue when a crafted stream is being mounted. This particular vulnerability is caused by a NULL pointer dereference in the init_journal function.
Comment 1 Daniel Drake (RETIRED) gentoo-dev 2006-12-23 08:52:29 UTC
Appears to be unfixed and unreported, filed a bug upstream:
http://bugzilla.kernel.org/show_bug.cgi?id=7738
Comment 2 Daniel Drake (RETIRED) gentoo-dev 2007-01-01 20:16:19 UTC
*** Bug 155355 has been marked as a duplicate of this bug. ***
Comment 3 unnamedrambler 2008-03-07 02:37:19 UTC
This one took some digging
Proposed metadata:
[linux < 2.6.21] via:
http://tree.celinuxforum.org/gitstat/commit-detail.php?commit=6c93fd1e578669364e026a0d44c669b871e2a8c4
https://bugzilla.redhat.com/show_bug.cgi?id=217008
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21
[gp < 2.6.21-1]
[gentoo < 2.6.21]


git commit id
6c93fd1e578669364e026a0d44c669b871e2a8c4