Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 467964 (CVE-2013-2017) - Kernel : veth: double-free flaw in case of congestion (CVE-2013-2017)
Summary: Kernel : veth: double-free flaw in case of congestion (CVE-2013-2017)
Status: RESOLVED FIXED
Alias: CVE-2013-2017
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-04-30 08:46 UTC by Agostino Sarubbo
Modified: 2021-10-25 00:34 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-04-30 08:46:28 UTC
From ${URL} :

A flaw was found in the way Virtual Ethernet driver implementation in the Linux kernel handled skbs 
in case of congestion.

A remote attacker could potentially use this flaw to crash the system.

Introduced in:
2.6.33-rc1

Fixed in:
2.6.34

Upstream fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6ec82562ffc6f297d0de36d65776cff8e5704867

References:
http://marc.info/?l=linux-netdev&m=127310770900442&w=3
Comment 1 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2015-08-10 17:55:11 UTC
=sys-kernel/pf-sources-2.6.33_p4

only place this could still exist I think
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-10-25 00:34:45 UTC
No affected kernels in tree